Підтримка
Цілодобова підтримка | Правила звернення

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Поширені запитання |  Форум |  Бот самопідтримки Telegram

Ваші запити

  • Всі: -
  • Незакриті: -
  • Останій: -

Зателефонуйте

Глобальна підтримка:
+7 (495) 789-45-86

Зв'яжіться з нами Незакриті запити: 

Профіль

Профіль

Trojan.Siggen9.46681

Добавлен в вирусную базу Dr.Web: 2020-05-17

Описание добавлено:

Technical Information

To ensure autorun and distribution
Modifies the following registry keys
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 98' = '<SYSTEM32>\WScript.exe "C:\$Recycle.Bin\S-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 35' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\sdhelp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 65' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\sdinvoker\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 84' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\sdloader\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 43' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\sdraw\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 87' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SDTrayApp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 85' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SeaMonkey\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 20' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\seccenter\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 68' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SFAgent\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 34' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\sigtool\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 6' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\simpress\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 90' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SiteCli\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 87' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\skype\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 22' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\skypePM\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 25' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SmartFTP\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 8' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\smath\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 30' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Smc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 25' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SNDSrvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\sniffer\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 55' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\so3d\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 77' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\sched\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 39' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\soffice\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 64' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ScanningProcess\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 67' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\scalc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 38' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Realmon\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 98' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Reference Assemblies\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 53' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\register\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\removeit\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Remover\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 37' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Rescue\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 30' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\rfwmain\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 58' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\RQ\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 45' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Rtvscan\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 95' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\RuLaunch\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\RunSetup\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 9' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Safari\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 27' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\sarcli\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 61' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\sargui\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 40' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SAVAdminService\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 35' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SAVMain\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\savprogress\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SAVScan\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 21' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\sbase\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\scanner\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 66' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SPAMCFG\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 45' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SPBBCSvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 54' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\spider\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 15' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\tgsvcstp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 11' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\thebat\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 77' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\THGnard\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 64' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Thunderbird\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 22' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Tmas\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 86' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\tmlisten\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 0' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Tmntsrv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 83' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\TmPfw\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\uiscan\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 22' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\tmproxy\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 94' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Totalcmd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 59' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\tracelog\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Traymon\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 5' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\trillian\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 72' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\TrojanGuarder\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 27' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\TrojanHunter\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 64' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\trtddptr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 43' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\TwelveSky2\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 54' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\tca\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 29' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\TeaTimer\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 6' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\TBMon\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 97' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Sysinfo\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SymWSC\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\spidernt\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 84' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Spiderui\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 80' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\sporder\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SpybotSD\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 98' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\sro_client\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\start_diag\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 90' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\stopsignav\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 26' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\StreetsOlkShim\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 91' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\rcimlby\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 45' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\svcntaux\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 15' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SubmitFiles\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 15' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\swdoctor\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 38' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\swdsvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 29' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\sweb\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 95' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\swriter\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 26' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SymantecRootInstaller\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\symlcsvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 85' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SymProxySvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 76' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\SymSPort\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 29' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\spiderml\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 86' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\swAgent\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 40' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\tnbutil\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 71' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\RavTimer\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 19' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\qhwscsvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 4' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\oget\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\olAddin\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 48' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\OnAccessInstaller\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\opera\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 53' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\osCheck\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 54' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\outlook\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 18' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\outpost\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 36' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PartIn\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 95' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PartIn9x\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 53' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\partinfo\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 72' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PartInNT\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PavFires\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 21' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PavFnSvr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 31' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Pavkre\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 85' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PavProt\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 95' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\pavProxy\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 2' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\pavprsrv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 36' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\pavsrv51\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 52' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\pccguide\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 36' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\OfcPfwSvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 74' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\pccntmon\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\oaui\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 11' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\NWService\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 46' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\nisoptui\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 89' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\nod\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\nod32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 5' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\nod32krn\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 92' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\nod32kui\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 74' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\NotifyHA\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 23' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\notstart\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 26' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\npavtray\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 37' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\npfmsg\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 38' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\NSMdtr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\NssServ\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 22' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\NssTray\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 50' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ntoskrnl\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ntrtscan\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 91' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\NTXconfig\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 89' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Nupgrade\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 7' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Nvcod\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 2' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Nvcte\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 79' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Nvcut\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 1' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\oasrv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 40' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PCCPFW\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 19' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PcCtlCom\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 46' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PCTAV\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\pshost\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 13' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PsImSvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 56' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PXAgent\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PXConsole\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 11' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PXL\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PXL1\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 14' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PXReset\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 93' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\pxsupport\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 76' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\RAT\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 0' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\python\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 27' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\qip\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 31' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\qklez\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 78' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\qrtfix\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 33' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\quaranti\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 76' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\quickstart\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 35' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Ragexe\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 36' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\RagFree\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 66' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\rapget\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 66' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ps\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 80' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\psctrls\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 23' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\protect\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 29' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ProcessViewer\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 76' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PrivateBrowser\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 40' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\pidgin\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 12' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PM\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 4' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PM8Flash\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 24' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PMagic\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 23' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PMagic9x\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 18' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PMagicBT\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PMagicNT\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 24' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\POLUTIL\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 68' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\RavMon\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 34' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ppfw\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 41' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\postinstall\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 70' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\pqbw\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 34' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PqPe\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 94' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\pqpe9x\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\pqpent\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 86' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\preconfig\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 6' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\preupd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 41' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\prevsrv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 36' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\PrevxSetup\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 89' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\pertsk\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 22' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Pqboot32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 5' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\una\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 60' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Uninstall Information\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 86' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\UninstallCAVS\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 8' = '<SYSTEM32>\WScript.exe "%PROGRAMDATA%\Oracle\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49' = '<SYSTEM32>\WScript.exe "%PROGRAMDATA%\Package Cache\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 93' = '<SYSTEM32>\WScript.exe "%PROGRAMDATA%\Start Menu\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 14' = '<SYSTEM32>\WScript.exe "%PROGRAMDATA%\Sun\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 59' = '<SYSTEM32>\WScript.exe "%PROGRAMDATA%\Templates\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 86' = '<SYSTEM32>\WScript.exe "C:\Recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 9' = '<SYSTEM32>\WScript.exe "C:\totalcmd\LANGUAGE\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 68' = '<SYSTEM32>\WScript.exe "C:\Users\All Users\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 93' = '<SYSTEM32>\WScript.exe "%WINDIR%\Cursors\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 4' = '<SYSTEM32>\WScript.exe "C:\Users\Default\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 61' = '<SYSTEM32>\WScript.exe "C:\Users\Public\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 76' = '<SYSTEM32>\WScript.exe "%HOMEPATH%\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 13' = '<SYSTEM32>\WScript.exe "%WINDIR%\addins\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 76' = '<SYSTEM32>\WScript.exe "%WINDIR%\AppCompat\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 6' = '<SYSTEM32>\WScript.exe "%WINDIR%\AppPatch\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 32' = '<SYSTEM32>\WScript.exe "%WINDIR%\assembly\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 95' = '<SYSTEM32>\WScript.exe "%WINDIR%\BitLockerDiscoveryVolumeContents\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 2' = '<SYSTEM32>\WScript.exe "%WINDIR%\Branding\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 91' = '<SYSTEM32>\WScript.exe "%PROGRAMDATA%\Microsoft Toolkit\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 4' = '<SYSTEM32>\WScript.exe "%PROGRAMDATA%\Mozilla\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 76' = '<SYSTEM32>\WScript.exe "C:\Users\Default User\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 44' = '<SYSTEM32>\WScript.exe "%WINDIR%\CSC\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 97' = '<SYSTEM32>\WScript.exe "%PROGRAMDATA%\Favorites\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 12' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Pidgin\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 45' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\QIP 2012\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 42' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Reference Assemblies\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Steam\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 82' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Uninstall Information\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 30' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Winamp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 35' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Windows Defender\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 58' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Windows Mail\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 98' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Windows Media Player\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 96' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Windows NT\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 25' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Windows Photo Viewer\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Windows Portable Devices\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 89' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Windows Sidebar\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 39' = '<SYSTEM32>\WScript.exe "%PROGRAMDATA%\Adobe\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 65' = '<SYSTEM32>\WScript.exe "%PROGRAMDATA%\Application Data\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49' = '<SYSTEM32>\WScript.exe "%PROGRAMDATA%\Desktop\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 37' = '<SYSTEM32>\WScript.exe "%PROGRAMDATA%\Documents\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 13' = '<SYSTEM32>\WScript.exe "%PROGRAMDATA%\Microsoft\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\MSBuild\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 71' = '<SYSTEM32>\WScript.exe "%PROGRAMDATA%\Microsoft Help\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 54' = '<SYSTEM32>\WScript.exe "%WINDIR%\Web\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17' = '<SYSTEM32>\WScript.exe "%WINDIR%\debug\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 41' = '<SYSTEM32>\WScript.exe "%WINDIR%\RemotePackages\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 16' = '<SYSTEM32>\WScript.exe "%WINDIR%\SchCache\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 75' = '<SYSTEM32>\WScript.exe "%WINDIR%\schemas\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 12' = '<SYSTEM32>\WScript.exe "%WINDIR%\security\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 27' = '<SYSTEM32>\WScript.exe "%WINDIR%\ServiceProfiles\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 97' = '<SYSTEM32>\WScript.exe "%WINDIR%\Setup\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 68' = '<SYSTEM32>\WScript.exe "%WINDIR%\ShellNew\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 58' = '<SYSTEM32>\WScript.exe "%WINDIR%\SoftwareDistribution\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 45' = '<SYSTEM32>\WScript.exe "%WINDIR%\Speech\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%WINDIR%\DigitalLocker\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 4' = '<SYSTEM32>\WScript.exe "%WINDIR%\system\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17' = '<SYSTEM32>\WScript.exe "%WINDIR%\SysWOW64\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 68' = '<SYSTEM32>\WScript.exe "%WINDIR%\TAPI\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62' = '<SYSTEM32>\WScript.exe "%WINDIR%\Tasks\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 60' = '<SYSTEM32>\WScript.exe "%WINDIR%\Temp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63' = '<SYSTEM32>\WScript.exe "%WINDIR%\tracing\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 32' = '<SYSTEM32>\WScript.exe "%WINDIR%\twain_32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 87' = '<SYSTEM32>\WScript.exe "%WINDIR%\Vss\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 59' = '<SYSTEM32>\WScript.exe "%WINDIR%\Registration\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 43' = '<SYSTEM32>\WScript.exe "%WINDIR%\Prefetch\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 77' = '<SYSTEM32>\WScript.exe "%WINDIR%\Resources\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 92' = '<SYSTEM32>\WScript.exe "%WINDIR%\PolicyDefinitions\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 59' = '<SYSTEM32>\WScript.exe "%WINDIR%\PLA\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 69' = '<SYSTEM32>\WScript.exe "%WINDIR%\Downloaded Program Files\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 80' = '<SYSTEM32>\WScript.exe "%WINDIR%\en-US\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 37' = '<SYSTEM32>\WScript.exe "%WINDIR%\Fonts\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 15' = '<SYSTEM32>\WScript.exe "%WINDIR%\Globalization\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 1' = '<SYSTEM32>\WScript.exe "%WINDIR%\Help\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 70' = '<SYSTEM32>\WScript.exe "%WINDIR%\IME\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 2' = '<SYSTEM32>\WScript.exe "%WINDIR%\inf\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 41' = '<SYSTEM32>\WScript.exe "%WINDIR%\Installer\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 15' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Mozilla Thunderbird\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 87' = '<SYSTEM32>\WScript.exe "%WINDIR%\L2Schemas\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 15' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Opera\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 48' = '<SYSTEM32>\WScript.exe "%WINDIR%\Logs\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 11' = '<SYSTEM32>\WScript.exe "%WINDIR%\Microsoft.NET\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 100' = '<SYSTEM32>\WScript.exe "%WINDIR%\Migration\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 92' = '<SYSTEM32>\WScript.exe "%WINDIR%\ModemLogs\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 87' = '<SYSTEM32>\WScript.exe "%WINDIR%\Offline Web Pages\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 53' = '<SYSTEM32>\WScript.exe "%WINDIR%\Panther\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 98' = '<SYSTEM32>\WScript.exe "%WINDIR%\PCHEALTH\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 54' = '<SYSTEM32>\WScript.exe "%WINDIR%\Performance\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 55' = '<SYSTEM32>\WScript.exe "%WINDIR%\LiveKernelReports\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 33' = '<SYSTEM32>\WScript.exe "%WINDIR%\ehome\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 22' = '<SYSTEM32>\WScript.exe "%WINDIR%\Media\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 39' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Mozilla Firefox\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 31' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\mIRC\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 29' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Microsoft.NET\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 72' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\VisthLic\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 89' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\VisthUpd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 12' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\vrfwsvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 67' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\vrmonsvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 94' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\vrrw32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 34' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Vshwin32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 68' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\vsmon\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 42' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\vsserv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 59' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\VsStat\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 85' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Wclose\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 96' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\webfiltr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 46' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\WebMoney\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 16' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\WebProxy\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 30' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\WebScanX\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 32' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\wil\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 42' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Winaw32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 30' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\winbaram\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 95' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\VirusKeeper\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 82' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\viritexp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 84' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\VistAux\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 69' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\viritsvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 77' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\VetTray\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 20' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\UPSObMaker\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 50' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\UninstallLSP\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 28' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\unoinfo\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 1' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\unopkg\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 73' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\unp_test\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 30' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Up2Date\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 14' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Updater\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 82' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\UpdaterUI\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 40' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\updclient\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 9' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\wincmd32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 65' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\netxray\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 32' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\upgrepl\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 76' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\UUpd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 83' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Vba32ECM\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 19' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Vba32ifs\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 28' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\vba32ldr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 67' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Vba32PP3\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 2' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\VBSNTW\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 7' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\vchk\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\vcrmon\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 55' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Uninstaller\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 55' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\USDownloader\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 98' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\winss\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 67' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\WindowList\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Windows Media Player\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\YahooSync\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 34' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ybclient\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 2' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Ymsgr_tray\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 66' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\zapro\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\zatutor\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 0' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\zauninst\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 31' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\zlclient\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 78' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\VirusNews\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 19' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\zonealarm\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 12' = '<SYSTEM32>\WScript.exe "%CommonProgramFiles(x86)%\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 36' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Google\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 9' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Internet Explorer\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 1' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\K-Lite Codec Pack\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Microsoft Analysis Services\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 89' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Microsoft Office\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 22' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Microsoft Visual Studio .NET 2003\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 74' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Microsoft Visual Studio 8\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 43' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\wsm\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57' = '<SYSTEM32>\WScript.exe "%ProgramFiles(x86)%\Adobe\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 97' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\YahooMessenger\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 29' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\xcommsvr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\wsftpgui\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 60' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\wsctool\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 93' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Windows NT\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 7' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Windows Photo Viewer\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 38' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Windows Portable Devices\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 43' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Windows Sidebar\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 79' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\windump\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 90' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\WinMail\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 97' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\WinRAR\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 50' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Windows Defender\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 73' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\winroute\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 99' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Windows Journal\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 30' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\winssnotify\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 68' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\WLLoginProxy\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 52' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\wlmail\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 79' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\wltuser\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\woool\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 99' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\wow\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 6' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\WrAdmin\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 0' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\WrCtrl\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Windows Mail\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\writespid\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 8' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\wish\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 84' = '<SYSTEM32>\WScript.exe "<SYSTEM32>\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 35' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\NetstatViewer\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 90' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\MVC\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 75' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CavQ\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 25' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CAVSCons\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 18' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\cavse\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 26' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CavSn\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 82' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CavSub\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CAVSubmit\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 41' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CavUMAS\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 95' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CavUserUpd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 92' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Cavvl\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 0' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ccapp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 65' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ccEvtMgr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CCleaner\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 72' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ccProxy\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 38' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ccSetMgr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 43' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CEmRep\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 35' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\chrome\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 83' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\clamscan\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 35' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ClamTray\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 88' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ClamWin\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 75' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Cavoar\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 23' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Claw95\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 6' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CavMUD\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 25' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CavEmSrv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 81' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\bdmcon\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 39' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\bdnews\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\bdoesrv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 4' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\bdss\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 46' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\bdsubmit\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 6' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\bdsubmitwiz\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 86' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\BDSurvey\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 11' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\bdswitch\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 12' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\bdwizreg\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\blackd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 71' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\blackice\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 14' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\blindman\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 52' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\BTIni\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 28' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\BTIniNT\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 54' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\cabalmain\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 52' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\cafix\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 1' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CavApp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CaVasm\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 96' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CavAUD\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 14' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Cavmr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 83' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Claw95cf\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 75' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\cleaner\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 78' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\cleaner3\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 84' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\DrVirus\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 93' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\DrvMap\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 30' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\drwadins\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 45' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\drweb\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 65' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\drweb32w\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 80' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\drweb386\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 8' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\drwebscd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 21' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Drwebupw\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 48' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ewidoctrl\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 30' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\drwebwcl\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 61' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\DVD Maker\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 2' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ecmd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 90' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\egni\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 64' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ehsniffer\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 34' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ekrn\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 59' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\elementclient\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 15' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\etherd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 26' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Eudora\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 66' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\dpatrolq\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 50' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\drvctl\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 77' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\dnf\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 66' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\dislite\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 50' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\DirectFTP\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\clrcche\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 73' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CMain\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 1' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CMGrdian\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 50' = '<SYSTEM32>\WScript.exe "%CommonProgramFiles%\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 43' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\copyx64\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 18' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Courier\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 20' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\cpd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 56' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CSendTo\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\bdagent\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 48' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\custinstall\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 67' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\cssexc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 5' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\cuteftp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 81' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\DBConvert\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 40' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\DBTool\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 2' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\defensewall\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 13' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\DefWatch\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 24' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\dekaron\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 34' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Digsby\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 77' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\digsby-app\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 47' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\CliSvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 55' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\custsetup\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 27' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\drwreg\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\BackWeb-4476822\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 32' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avgwizfw\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\AhnSD\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 48' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\aim6\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 32' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\aimpro\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 48' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\airdefense\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 16' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ALMon\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 6' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ALsvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\amon\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 33' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\amsn\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 53' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Anti-Trojan\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 35' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\AntiVirus\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 37' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\AolTbServer\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 81' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Armor2net\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 18' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\armorsurf\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 46' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ash\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 12' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashAvast\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashAvSrv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 14' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashchest\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 10' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashDisp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 86' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashDug\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 73' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ageofconan\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 61' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashEnhcd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 87' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Agb5\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 14' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\AckWin32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 27' = '<SYSTEM32>\WScript.exe "C:\Far2\Addons\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 39' = '<SYSTEM32>\WScript.exe "C:\Far2\Documentation\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 35' = '<SYSTEM32>\WScript.exe "C:\Far2\Encyclopedia\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 70' = '<SYSTEM32>\WScript.exe "C:\Far2\FExcept\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 46' = '<SYSTEM32>\WScript.exe "C:\Far2\Plugins\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 53' = '<SYSTEM32>\WScript.exe "C:\Far2\PluginSDK\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 18' = '<SYSTEM32>\WScript.exe "C:\MSOCache\All Users\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 79' = '<SYSTEM32>\WScript.exe "C:\PerfLogs\Admin\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 68' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\360tray\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\a2cmd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 87' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\a2guard\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 7' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\a2HiJackFree\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 8' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\a2scan\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 81' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\a2service\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 36' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\a2start\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 71' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\a2upd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 7' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\a2wizard\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 44' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\aavshield\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 88' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\About\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 6' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\AdMunch\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 50' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashLogV\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 84' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashMaiSv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 46' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashPopWz\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 23' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avginet\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 58' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avgnpdln\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 18' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avgnpsvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 32' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avgrssvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 27' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avgscan\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 81' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avgupden\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 73' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avgupsvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 31' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avgvv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 96' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avsynmgr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 75' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avgw\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 61' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avinitnt\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 65' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\AvkServ\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 1' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\AVKService\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 87' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\AVKWCtl\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avnotify\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avpcc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 35' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avpm\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 45' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avscan\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 85' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avgemc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 79' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avgfwsrv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 17' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avgdiag\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 85' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avgcc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 28' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avgamsvr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 21' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashServ\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 61' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashsimp2\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 68' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashSimpl\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 68' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashSkPcc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 20' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashSkPck\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 48' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashUpd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 85' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashWebSv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 5' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ash_UpdateMediator\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 98' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\B2\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 68' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\aswUpdSv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 65' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\aswRegSvr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 42' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\AutostartExplorer\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 61' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\AutoTrace\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 86' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avadmin\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 33' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avcenter\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 21' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avciman\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 85' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avcmd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 60' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\avconfig\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 9' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Avconsol\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ashQuick\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 86' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\AutoDown\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 38' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\exit_av\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 47' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\EzAntivirusRegistrationCheck\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\F-Sched\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 13' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\iTunes\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 72' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Java\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\k-meleon\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 14' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\KAV\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 35' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\kavmm\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 11' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\KAVPF\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 59' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\KavPFW\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 7' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\KAVStart\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\LuConfig\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 34' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\KAVSvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Launcher\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\licmgr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 5' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\livesrv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 13' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\LiveUpdate\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 65' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\LogWatNT\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 6' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\lotroclient\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 40' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\lpfw\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 32' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\LUCallbackProxy\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 14' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ISSVC\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 19' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\isUAC\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 2' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\konnekt\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 66' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\LUCheck\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 46' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\isafe\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 82' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ImApp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 40' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ImNotfy\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 56' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ImpCnt\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 6' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\IncMail\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\InocIT\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 58' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\InoRpc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 68' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\InoRT\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 4' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\InoTask\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 88' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\InoUpTNG\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 74' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\InphaseNXD\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\InstallCAVS\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 94' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\InstallLicense\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 46' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\InstallLSP\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\InstLsp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 2' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Internet Explorer\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 24' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\iris\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 4' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\iron\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 15' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ISPNews\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 72' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ih8run\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 90' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\isPwdsvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 82' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\NeoWatchLog\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 96' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\LUInit\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 34' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\MP3ToysTray\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 57' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\MpEng\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\mpftray\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 100' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\mpssvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 83' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\MSBuild\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 92' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\msimn\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\MSMPSVC\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 45' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\msn6\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 27' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\msnmsgr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 38' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Luna\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 40' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\mva\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 71' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\myAgtSvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 54' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\myagttry\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 74' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\navapsvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 77' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\NavLu32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 74' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\NAVStub\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 78' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Navw32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 24' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Navwnt\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 77' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\MP3Toys\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 78' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\MP3Theater\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 14' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\MP3Tray\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 51' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\MonSysNT\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 5' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\monlite\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 52' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Luupdate\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 4' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\MalwareRemoval\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 95' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\maplestory\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Maxthon\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\mcmnhdlr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 95' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\mcregwiz\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 70' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Mcshield\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 22' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\mcupdmgr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 7' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ih8\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 52' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\mcvsshld\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 73' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ILAUNCHR\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 85' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\mfpmp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 67' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Microsoft Office\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 62' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Microsoft SQL Server Compact Edition\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 79' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Microsoft Sync Framework\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 10' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Microsoft Synchronization Services\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 89' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Mir3Game\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 77' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\miranda32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 11' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Miro\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 46' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\MemString\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 6' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\magent\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 2' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Microsoft Analysis Services\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 54' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\iexplore\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 3' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ieuser\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 30' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\IERegFix\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 74' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsavaui\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 1' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsavgui\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 78' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsavstrt\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 89' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsavwsch\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 82' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsavwscr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 91' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsbwsys\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 90' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsdbuh\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 35' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsdc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 13' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsdfwd\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 0' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FSDIAG\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 72' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FsDiagUi\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 78' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsfwwsch\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 45' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsfwwscr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 55' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsgetwab\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 85' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsgk32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 38' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsgk32st\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 88' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsguidll\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 41' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsauach\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 21' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsample\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 1' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsav32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 66' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsaua\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 74' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\freshclam\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 68' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FlashFXP\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 22' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\far\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 13' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FCH32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 20' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fdm\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 53' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fdmwi\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 15' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\filezilla\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 90' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\firebird\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 52' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FireFox\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 4' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FireSvc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 79' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsguiexe\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 11' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\NeoWatchTray\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 46' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FireTray\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 69' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\flock\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 3' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Foxit\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 65' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FPAVServer\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 56' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fpavupdm\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 48' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FProtTray\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 93' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fpscan\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 43' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fptrayproc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 5' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FPWin\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 9' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FAMEH32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 27' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FlashGot\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 98' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fssg\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 83' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FSHDLL32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 25' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsihs\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 42' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\GoogleDesktop\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 98' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\googletalk\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 87' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\GoogleUpdate\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 49' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\guardgni\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 90' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\GuardNT\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 30' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\gw\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 88' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\helpctr\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 78' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsav\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 68' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\helper\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 83' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\HRegMon\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 97' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\Hrres\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 73' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\HSockPE\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 13' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\httplook\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 25' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\iamapp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 55' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\iamserv\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 64' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ICQ\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ICQLite\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 37' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\GIANTAntiSpywareMain\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 90' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\hipsdiag\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 37' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\gnotify\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 75' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\GIANTAntiSpywareUpdater\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 3' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\gg\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 11' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ge\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 77' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FSLAUNCH\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 43' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FSM32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 48' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FSMA32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 18' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FSMB32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 69' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fspc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 77' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fspex\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 41' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsqh\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 63' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fshelp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 79' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fssf\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 86' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\FSHOTFIX\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 94' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fssm32\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 20' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fssw\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 23' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fstlui\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 90' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsuninst\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 32' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsus\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 71' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\ftpte\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 70' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\gc\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 77' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\gcasDtServ\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 96' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsihcomp\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 16' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\gcasServ\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 13' = '<SYSTEM32>\WScript.exe "%ProgramFiles%\fsstm\<File name>.vbs"'
  • [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'System Patch 1' = '<SYSTEM32>\WScript.exe "D:\$RECYCLE.BIN\S-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs"'
Creates or modifies the following files
  • %WINDIR%\tasks\<File name>.vbs
Creates the following files on removable media
  • <Drive name for removable media>:\autorun.inf
  • <Drive name for removable media>:\<File name>.vbs
Malicious functions
To complicate detection of its presence in the operating system,
forces the system hide from view:
  • file extensions
Modifies file system
Creates the following files
  • C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs
  • %ProgramFiles%\sdhelp\<File name>.vbs
  • %ProgramFiles%\sdinvoker\<File name>.vbs
  • %ProgramFiles%\sdloader\<File name>.vbs
  • %ProgramFiles%\sdraw\<File name>.vbs
  • %ProgramFiles%\sdtrayapp\<File name>.vbs
  • %ProgramFiles%\seamonkey\<File name>.vbs
  • %ProgramFiles%\seccenter\<File name>.vbs
  • %ProgramFiles%\sfagent\<File name>.vbs
  • %ProgramFiles%\sigtool\<File name>.vbs
  • %ProgramFiles%\simpress\<File name>.vbs
  • %ProgramFiles%\sitecli\<File name>.vbs
  • %ProgramFiles%\skype\<File name>.vbs
  • %ProgramFiles%\skypepm\<File name>.vbs
  • %ProgramFiles%\smartftp\<File name>.vbs
  • %ProgramFiles%\smath\<File name>.vbs
  • %ProgramFiles%\smc\<File name>.vbs
  • %ProgramFiles%\sndsrvc\<File name>.vbs
  • %ProgramFiles%\sniffer\<File name>.vbs
  • %ProgramFiles%\so3d\<File name>.vbs
  • %ProgramFiles%\sched\<File name>.vbs
  • %ProgramFiles%\ravtimer\<File name>.vbs
  • %ProgramFiles%\scanningprocess\<File name>.vbs
  • %ProgramFiles%\scalc\<File name>.vbs
  • %ProgramFiles%\realmon\<File name>.vbs
  • %ProgramFiles%\reference assemblies\<File name>.vbs
  • %ProgramFiles%\register\<File name>.vbs
  • %ProgramFiles%\removeit\<File name>.vbs
  • %ProgramFiles%\remover\<File name>.vbs
  • %ProgramFiles%\rescue\<File name>.vbs
  • %ProgramFiles%\rfwmain\<File name>.vbs
  • %ProgramFiles%\rq\<File name>.vbs
  • %ProgramFiles%\rtvscan\<File name>.vbs
  • %ProgramFiles%\rulaunch\<File name>.vbs
  • %ProgramFiles%\runsetup\<File name>.vbs
  • %ProgramFiles%\safari\<File name>.vbs
  • %ProgramFiles%\sarcli\<File name>.vbs
  • %ProgramFiles%\sargui\<File name>.vbs
  • %ProgramFiles%\savadminservice\<File name>.vbs
  • %ProgramFiles%\savmain\<File name>.vbs
  • %ProgramFiles%\savprogress\<File name>.vbs
  • %ProgramFiles%\savscan\<File name>.vbs
  • %ProgramFiles%\sbase\<File name>.vbs
  • %ProgramFiles%\scanner\<File name>.vbs
  • %ProgramFiles%\rcimlby\<File name>.vbs
  • %ProgramFiles%\soffice\<File name>.vbs
  • %ProgramFiles%\spiderml\<File name>.vbs
  • %ProgramFiles%\tca\<File name>.vbs
  • %ProgramFiles%\teatimer\<File name>.vbs
  • %ProgramFiles%\tgsvcstp\<File name>.vbs
  • %ProgramFiles%\thebat\<File name>.vbs
  • %ProgramFiles%\thgnard\<File name>.vbs
  • %ProgramFiles%\thunderbird\<File name>.vbs
  • %ProgramFiles%\tmas\<File name>.vbs
  • %ProgramFiles%\tmlisten\<File name>.vbs
  • %ProgramFiles%\rat\<File name>.vbs
  • %ProgramFiles%\tmntsrv\<File name>.vbs
  • %ProgramFiles%\tmproxy\<File name>.vbs
  • %ProgramFiles%\tnbutil\<File name>.vbs
  • %ProgramFiles%\totalcmd\<File name>.vbs
  • %ProgramFiles%\tracelog\<File name>.vbs
  • %ProgramFiles%\traymon\<File name>.vbs
  • %ProgramFiles%\trillian\<File name>.vbs
  • %ProgramFiles%\trojanguarder\<File name>.vbs
  • %ProgramFiles%\trojanhunter\<File name>.vbs
  • %ProgramFiles%\sysinfo\<File name>.vbs
  • %ProgramFiles%\tbmon\<File name>.vbs
  • %ProgramFiles%\spbbcsvc\<File name>.vbs
  • %ProgramFiles%\spamcfg\<File name>.vbs
  • %ProgramFiles%\symproxysvc\<File name>.vbs
  • %ProgramFiles%\spidernt\<File name>.vbs
  • %ProgramFiles%\spiderui\<File name>.vbs
  • %ProgramFiles%\sporder\<File name>.vbs
  • %ProgramFiles%\spybotsd\<File name>.vbs
  • %ProgramFiles%\sro_client\<File name>.vbs
  • %ProgramFiles%\start_diag\<File name>.vbs
  • %ProgramFiles%\stopsignav\<File name>.vbs
  • %ProgramFiles%\streetsolkshim\<File name>.vbs
  • %ProgramFiles%\submitfiles\<File name>.vbs
  • %ProgramFiles%\svcntaux\<File name>.vbs
  • %ProgramFiles%\swagent\<File name>.vbs
  • %ProgramFiles%\swdoctor\<File name>.vbs
  • %ProgramFiles%\swdsvc\<File name>.vbs
  • %ProgramFiles%\sweb\<File name>.vbs
  • %ProgramFiles%\swriter\<File name>.vbs
  • %ProgramFiles%\symantecrootinstaller\<File name>.vbs
  • %ProgramFiles%\symlcsvc\<File name>.vbs
  • %ProgramFiles%\symsport\<File name>.vbs
  • %ProgramFiles%\spider\<File name>.vbs
  • %ProgramFiles%\symwsc\<File name>.vbs
  • %ProgramFiles%\ravmon\<File name>.vbs
  • %ProgramFiles%\rapget\<File name>.vbs
  • %ProgramFiles%\twelvesky2\<File name>.vbs
  • %ProgramFiles%\oladdin\<File name>.vbs
  • %ProgramFiles%\onaccessinstaller\<File name>.vbs
  • %ProgramFiles%\opera\<File name>.vbs
  • %ProgramFiles%\oscheck\<File name>.vbs
  • %ProgramFiles%\outlook\<File name>.vbs
  • %ProgramFiles%\outpost\<File name>.vbs
  • %ProgramFiles%\partin\<File name>.vbs
  • %ProgramFiles%\partin9x\<File name>.vbs
  • %ProgramFiles%\partinfo\<File name>.vbs
  • %ProgramFiles%\partinnt\<File name>.vbs
  • %ProgramFiles%\pavfires\<File name>.vbs
  • %ProgramFiles%\pavfnsvr\<File name>.vbs
  • %ProgramFiles%\pavkre\<File name>.vbs
  • %ProgramFiles%\pavprot\<File name>.vbs
  • %ProgramFiles%\pavproxy\<File name>.vbs
  • %ProgramFiles%\pavprsrv\<File name>.vbs
  • %ProgramFiles%\pavsrv51\<File name>.vbs
  • %ProgramFiles%\oaui\<File name>.vbs
  • %ProgramFiles%\oasrv\<File name>.vbs
  • %ProgramFiles%\oget\<File name>.vbs
  • %ProgramFiles%\pccpfw\<File name>.vbs
  • %ProgramFiles%\pccguide\<File name>.vbs
  • %ProgramFiles%\pccntmon\<File name>.vbs
  • %ProgramFiles%\nod\<File name>.vbs
  • %ProgramFiles%\nod32\<File name>.vbs
  • %ProgramFiles%\nod32krn\<File name>.vbs
  • %ProgramFiles%\nod32kui\<File name>.vbs
  • %ProgramFiles%\notifyha\<File name>.vbs
  • %ProgramFiles%\notstart\<File name>.vbs
  • %ProgramFiles%\npavtray\<File name>.vbs
  • %ProgramFiles%\npfmsg\<File name>.vbs
  • %ProgramFiles%\nsmdtr\<File name>.vbs
  • %ProgramFiles%\nssserv\<File name>.vbs
  • %ProgramFiles%\nsstray\<File name>.vbs
  • %ProgramFiles%\ntoskrnl\<File name>.vbs
  • %ProgramFiles%\ntrtscan\<File name>.vbs
  • %ProgramFiles%\ntxconfig\<File name>.vbs
  • %ProgramFiles%\nupgrade\<File name>.vbs
  • %ProgramFiles%\nvcod\<File name>.vbs
  • %ProgramFiles%\nvcte\<File name>.vbs
  • %ProgramFiles%\nwservice\<File name>.vbs
  • %ProgramFiles%\netxray\<File name>.vbs
  • %ProgramFiles%\nvcut\<File name>.vbs
  • %ProgramFiles%\pcctlcom\<File name>.vbs
  • %ProgramFiles%\ps\<File name>.vbs
  • %ProgramFiles%\pidgin\<File name>.vbs
  • %ProgramFiles%\psimsvc\<File name>.vbs
  • %ProgramFiles%\pxagent\<File name>.vbs
  • %ProgramFiles%\pxconsole\<File name>.vbs
  • %ProgramFiles%\pxl\<File name>.vbs
  • %ProgramFiles%\pxl1\<File name>.vbs
  • %ProgramFiles%\pxreset\<File name>.vbs
  • %ProgramFiles%\pxsupport\<File name>.vbs
  • %ProgramFiles%\ofcpfwsvc\<File name>.vbs
  • %ProgramFiles%\python\<File name>.vbs
  • %ProgramFiles%\qip\<File name>.vbs
  • %ProgramFiles%\qklez\<File name>.vbs
  • %ProgramFiles%\qrtfix\<File name>.vbs
  • %ProgramFiles%\quaranti\<File name>.vbs
  • %ProgramFiles%\quickstart\<File name>.vbs
  • %ProgramFiles%\ragexe\<File name>.vbs
  • %ProgramFiles%\ragfree\<File name>.vbs
  • %ProgramFiles%\protect\<File name>.vbs
  • %ProgramFiles%\processviewer\<File name>.vbs
  • %ProgramFiles%\qhwscsvc\<File name>.vbs
  • %ProgramFiles%\pshost\<File name>.vbs
  • %ProgramFiles%\psctrls\<File name>.vbs
  • %ProgramFiles%\privatebrowser\<File name>.vbs
  • %ProgramFiles%\prevxsetup\<File name>.vbs
  • %ProgramFiles%\pm\<File name>.vbs
  • %ProgramFiles%\pm8flash\<File name>.vbs
  • %ProgramFiles%\pmagic\<File name>.vbs
  • %ProgramFiles%\pmagic9x\<File name>.vbs
  • %ProgramFiles%\pmagicbt\<File name>.vbs
  • %ProgramFiles%\pmagicnt\<File name>.vbs
  • %ProgramFiles%\trtddptr\<File name>.vbs
  • %ProgramFiles%\polutil\<File name>.vbs
  • %ProgramFiles%\ppfw\<File name>.vbs
  • %ProgramFiles%\tmpfw\<File name>.vbs
  • %ProgramFiles%\pqboot32\<File name>.vbs
  • %ProgramFiles%\pqpe\<File name>.vbs
  • %ProgramFiles%\pqpe9x\<File name>.vbs
  • %ProgramFiles%\pqpent\<File name>.vbs
  • %ProgramFiles%\preconfig\<File name>.vbs
  • %ProgramFiles%\preupd\<File name>.vbs
  • %ProgramFiles%\prevsrv\<File name>.vbs
  • %ProgramFiles%\postinstall\<File name>.vbs
  • %ProgramFiles%\pertsk\<File name>.vbs
  • %ProgramFiles%\pctav\<File name>.vbs
  • %ProgramFiles%\pqbw\<File name>.vbs
  • %ProgramFiles%\fssf\<File name>.vbs
  • %ProgramFiles%\uiscan\<File name>.vbs
  • %PROGRAMDATA%\microsoft\<File name>.vbs
  • %PROGRAMDATA%\microsoft help\<File name>.vbs
  • %PROGRAMDATA%\microsoft toolkit\<File name>.vbs
  • %PROGRAMDATA%\mozilla\<File name>.vbs
  • %PROGRAMDATA%\oracle\<File name>.vbs
  • %PROGRAMDATA%\package cache\<File name>.vbs
  • %PROGRAMDATA%\start menu\<File name>.vbs
  • %PROGRAMDATA%\sun\<File name>.vbs
  • %PROGRAMDATA%\templates\<File name>.vbs
  • C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<File name>.vbs
  • C:\totalcmd\language\<File name>.vbs
  • C:\users\default\<File name>.vbs
  • C:\users\public\<File name>.vbs
  • %HOMEPATH%\<File name>.vbs
  • %WINDIR%\addins\<File name>.vbs
  • %WINDIR%\appcompat\<File name>.vbs
  • %WINDIR%\apppatch\<File name>.vbs
  • %WINDIR%\assembly\<File name>.vbs
  • %WINDIR%\bitlockerdiscoveryvolumecontents\<File name>.vbs
  • %PROGRAMDATA%\favorites\<File name>.vbs
  • %WINDIR%\branding\<File name>.vbs
  • %PROGRAMDATA%\documents\<File name>.vbs
  • %PROGRAMDATA%\application data\<File name>.vbs
  • %ProgramFiles(x86)%\mirc\<File name>.vbs
  • %ProgramFiles(x86)%\mozilla firefox\<File name>.vbs
  • %ProgramFiles(x86)%\mozilla thunderbird\<File name>.vbs
  • %ProgramFiles(x86)%\msbuild\<File name>.vbs
  • %ProgramFiles(x86)%\opera\<File name>.vbs
  • %ProgramFiles(x86)%\pidgin\<File name>.vbs
  • %ProgramFiles(x86)%\qip 2012\<File name>.vbs
  • %ProgramFiles(x86)%\reference assemblies\<File name>.vbs
  • %ProgramFiles(x86)%\steam\<File name>.vbs
  • %ProgramFiles(x86)%\uninstall information\<File name>.vbs
  • %ProgramFiles(x86)%\winamp\<File name>.vbs
  • %ProgramFiles(x86)%\windows defender\<File name>.vbs
  • %ProgramFiles(x86)%\windows mail\<File name>.vbs
  • %ProgramFiles(x86)%\windows media player\<File name>.vbs
  • %ProgramFiles(x86)%\windows nt\<File name>.vbs
  • %ProgramFiles(x86)%\windows photo viewer\<File name>.vbs
  • %ProgramFiles(x86)%\windows portable devices\<File name>.vbs
  • %ProgramFiles(x86)%\windows sidebar\<File name>.vbs
  • %PROGRAMDATA%\adobe\<File name>.vbs
  • %PROGRAMDATA%\desktop\<File name>.vbs
  • %WINDIR%\csc\<File name>.vbs
  • %WINDIR%\cursors\<File name>.vbs
  • %WINDIR%\debug\<File name>.vbs
  • %WINDIR%\registration\<File name>.vbs
  • %WINDIR%\resources\<File name>.vbs
  • %WINDIR%\schcache\<File name>.vbs
  • %WINDIR%\schemas\<File name>.vbs
  • %WINDIR%\security\<File name>.vbs
  • %WINDIR%\serviceprofiles\<File name>.vbs
  • %WINDIR%\setup\<File name>.vbs
  • %WINDIR%\shellnew\<File name>.vbs
  • %WINDIR%\softwaredistribution\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft visual studio 8\<File name>.vbs
  • %WINDIR%\speech\<File name>.vbs
  • <SYSTEM32>\<File name>.vbs
  • %WINDIR%\syswow64\<File name>.vbs
  • %WINDIR%\tapi\<File name>.vbs
  • %WINDIR%\temp\<File name>.vbs
  • %WINDIR%\tracing\<File name>.vbs
  • %WINDIR%\twain_32\<File name>.vbs
  • %WINDIR%\vss\<File name>.vbs
  • %WINDIR%\prefetch\<File name>.vbs
  • %WINDIR%\policydefinitions\<File name>.vbs
  • %WINDIR%\remotepackages\<File name>.vbs
  • %WINDIR%\pla\<File name>.vbs
  • %WINDIR%\performance\<File name>.vbs
  • %WINDIR%\digitallocker\<File name>.vbs
  • %WINDIR%\ehome\<File name>.vbs
  • %WINDIR%\en-us\<File name>.vbs
  • %WINDIR%\fonts\<File name>.vbs
  • %WINDIR%\globalization\<File name>.vbs
  • %WINDIR%\help\<File name>.vbs
  • %WINDIR%\ime\<File name>.vbs
  • %WINDIR%\inf\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft.net\<File name>.vbs
  • %WINDIR%\installer\<File name>.vbs
  • %ProgramFiles%\netstatviewer\<File name>.vbs
  • %WINDIR%\livekernelreports\<File name>.vbs
  • %WINDIR%\media\<File name>.vbs
  • %WINDIR%\microsoft.net\<File name>.vbs
  • %WINDIR%\migration\<File name>.vbs
  • %WINDIR%\modemlogs\<File name>.vbs
  • %WINDIR%\offline web pages\<File name>.vbs
  • %WINDIR%\panther\<File name>.vbs
  • %WINDIR%\pchealth\<File name>.vbs
  • %WINDIR%\l2schemas\<File name>.vbs
  • %WINDIR%\downloaded program files\<File name>.vbs
  • %WINDIR%\logs\<File name>.vbs
  • %ProgramFiles%\nisoptui\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft office\<File name>.vbs
  • %ProgramFiles%\zlclient\<File name>.vbs
  • %ProgramFiles%\viritsvc\<File name>.vbs
  • %ProgramFiles%\viruskeeper\<File name>.vbs
  • %ProgramFiles%\virusnews\<File name>.vbs
  • %ProgramFiles%\vistaux\<File name>.vbs
  • %ProgramFiles%\visthlic\<File name>.vbs
  • %ProgramFiles%\visthupd\<File name>.vbs
  • %ProgramFiles%\vrfwsvc\<File name>.vbs
  • %ProgramFiles%\vrmonsvc\<File name>.vbs
  • %ProgramFiles%\vrrw32\<File name>.vbs
  • %ProgramFiles%\vshwin32\<File name>.vbs
  • %ProgramFiles%\vsmon\<File name>.vbs
  • %ProgramFiles%\vsserv\<File name>.vbs
  • %ProgramFiles%\vsstat\<File name>.vbs
  • %ProgramFiles%\wclose\<File name>.vbs
  • %ProgramFiles%\webfiltr\<File name>.vbs
  • %ProgramFiles%\webmoney\<File name>.vbs
  • %ProgramFiles%\webproxy\<File name>.vbs
  • %ProgramFiles%\webscanx\<File name>.vbs
  • %ProgramFiles%\vettray\<File name>.vbs
  • %ProgramFiles%\wil\<File name>.vbs
  • %ProgramFiles%\vcrmon\<File name>.vbs
  • %ProgramFiles%\vbsntw\<File name>.vbs
  • %ProgramFiles%\uninstall information\<File name>.vbs
  • %ProgramFiles%\uninstallcavs\<File name>.vbs
  • %ProgramFiles%\uninstaller\<File name>.vbs
  • %ProgramFiles%\uninstalllsp\<File name>.vbs
  • %ProgramFiles%\unoinfo\<File name>.vbs
  • %ProgramFiles%\unopkg\<File name>.vbs
  • %ProgramFiles%\unp_test\<File name>.vbs
  • %ProgramFiles%\up2date\<File name>.vbs
  • %ProgramFiles%\updater\<File name>.vbs
  • %ProgramFiles%\updaterui\<File name>.vbs
  • %ProgramFiles%\updclient\<File name>.vbs
  • %ProgramFiles%\upgrepl\<File name>.vbs
  • %ProgramFiles%\upsobmaker\<File name>.vbs
  • %ProgramFiles%\usdownloader\<File name>.vbs
  • %ProgramFiles%\uupd\<File name>.vbs
  • %ProgramFiles%\vba32ecm\<File name>.vbs
  • %ProgramFiles%\vba32ifs\<File name>.vbs
  • %ProgramFiles%\vba32ldr\<File name>.vbs
  • %ProgramFiles%\vba32pp3\<File name>.vbs
  • %ProgramFiles%\vchk\<File name>.vbs
  • %ProgramFiles%\winaw32\<File name>.vbs
  • %ProgramFiles%\winbaram\<File name>.vbs
  • %ProgramFiles%\wincmd32\<File name>.vbs
  • %ProgramFiles%\wsctool\<File name>.vbs
  • %ProgramFiles%\wsm\<File name>.vbs
  • %ProgramFiles%\xcommsvr\<File name>.vbs
  • %ProgramFiles%\yahoomessenger\<File name>.vbs
  • %ProgramFiles%\yahoosync\<File name>.vbs
  • %ProgramFiles%\ybclient\<File name>.vbs
  • %ProgramFiles%\ymsgr_tray\<File name>.vbs
  • %ProgramFiles%\zapro\<File name>.vbs
  • %ProgramFiles%\zatutor\<File name>.vbs
  • %ProgramFiles%\viritexp\<File name>.vbs
  • %ProgramFiles%\zauninst\<File name>.vbs
  • %ProgramFiles%\zonealarm\<File name>.vbs
  • %ProgramFiles(x86)%\adobe\<File name>.vbs
  • %CommonProgramFiles(x86)%\<File name>.vbs
  • %ProgramFiles(x86)%\google\<File name>.vbs
  • %ProgramFiles(x86)%\internet explorer\<File name>.vbs
  • %ProgramFiles(x86)%\k-lite codec pack\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft analysis services\<File name>.vbs
  • %ProgramFiles%\writespid\<File name>.vbs
  • %ProgramFiles%\wrctrl\<File name>.vbs
  • %ProgramFiles%\wsftpgui\<File name>.vbs
  • %ProgramFiles%\wradmin\<File name>.vbs
  • %ProgramFiles%\wow\<File name>.vbs
  • %ProgramFiles%\windowlist\<File name>.vbs
  • %ProgramFiles%\windows journal\<File name>.vbs
  • %ProgramFiles%\windows mail\<File name>.vbs
  • %ProgramFiles%\windows media player\<File name>.vbs
  • %ProgramFiles%\windows nt\<File name>.vbs
  • %ProgramFiles%\windows photo viewer\<File name>.vbs
  • %ProgramFiles%\windows portable devices\<File name>.vbs
  • %ProgramFiles%\windows sidebar\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft visual studio .net 2003\<File name>.vbs
  • %ProgramFiles%\windump\<File name>.vbs
  • %ProgramFiles%\una\<File name>.vbs
  • %ProgramFiles%\winrar\<File name>.vbs
  • %ProgramFiles%\winss\<File name>.vbs
  • %ProgramFiles%\winssnotify\<File name>.vbs
  • %ProgramFiles%\wish\<File name>.vbs
  • %ProgramFiles%\wlloginproxy\<File name>.vbs
  • %ProgramFiles%\wlmail\<File name>.vbs
  • %ProgramFiles%\wltuser\<File name>.vbs
  • %ProgramFiles%\woool\<File name>.vbs
  • %ProgramFiles%\winmail\<File name>.vbs
  • %ProgramFiles%\windows defender\<File name>.vbs
  • %ProgramFiles%\winroute\<File name>.vbs
  • %ProgramFiles%\neowatchtray\<File name>.vbs
  • %ProgramFiles%\neowatchlog\<File name>.vbs
  • %ProgramFiles%\navwnt\<File name>.vbs
  • %ProgramFiles%\cavse\<File name>.vbs
  • %ProgramFiles%\cavsn\<File name>.vbs
  • %ProgramFiles%\cavsub\<File name>.vbs
  • %ProgramFiles%\cavsubmit\<File name>.vbs
  • %ProgramFiles%\cavumas\<File name>.vbs
  • %ProgramFiles%\cavuserupd\<File name>.vbs
  • %ProgramFiles%\cavvl\<File name>.vbs
  • %ProgramFiles%\ccapp\<File name>.vbs
  • %ProgramFiles%\ccevtmgr\<File name>.vbs
  • %ProgramFiles%\ccleaner\<File name>.vbs
  • %ProgramFiles%\ccproxy\<File name>.vbs
  • %ProgramFiles%\ccsetmgr\<File name>.vbs
  • %ProgramFiles%\cemrep\<File name>.vbs
  • %ProgramFiles%\chrome\<File name>.vbs
  • %ProgramFiles%\clamscan\<File name>.vbs
  • %ProgramFiles%\clamtray\<File name>.vbs
  • %ProgramFiles%\clamwin\<File name>.vbs
  • %ProgramFiles%\cavoar\<File name>.vbs
  • %ProgramFiles%\cavmud\<File name>.vbs
  • %ProgramFiles%\cavscons\<File name>.vbs
  • %ProgramFiles%\cleaner\<File name>.vbs
  • %ProgramFiles%\claw95\<File name>.vbs
  • %ProgramFiles%\claw95cf\<File name>.vbs
  • %ProgramFiles%\bdoesrv\<File name>.vbs
  • %ProgramFiles%\bdss\<File name>.vbs
  • %ProgramFiles%\bdsubmit\<File name>.vbs
  • %ProgramFiles%\bdsubmitwiz\<File name>.vbs
  • %ProgramFiles%\bdsurvey\<File name>.vbs
  • %ProgramFiles%\bdswitch\<File name>.vbs
  • %ProgramFiles%\bdwizreg\<File name>.vbs
  • %ProgramFiles%\blackd\<File name>.vbs
  • %ProgramFiles%\blackice\<File name>.vbs
  • %ProgramFiles%\blindman\<File name>.vbs
  • %ProgramFiles%\btini\<File name>.vbs
  • %ProgramFiles%\btinint\<File name>.vbs
  • %ProgramFiles%\cabalmain\<File name>.vbs
  • %ProgramFiles%\cafix\<File name>.vbs
  • %ProgramFiles%\cavapp\<File name>.vbs
  • %ProgramFiles%\cavasm\<File name>.vbs
  • %ProgramFiles%\cavaud\<File name>.vbs
  • %ProgramFiles%\cavmr\<File name>.vbs
  • %ProgramFiles%\bdmcon\<File name>.vbs
  • %ProgramFiles%\cavemsrv\<File name>.vbs
  • %ProgramFiles%\cleaner3\<File name>.vbs
  • %ProgramFiles%\drvctl\<File name>.vbs
  • %ProgramFiles%\cmain\<File name>.vbs
  • %ProgramFiles%\drwadins\<File name>.vbs
  • %ProgramFiles%\drweb\<File name>.vbs
  • %ProgramFiles%\drweb32w\<File name>.vbs
  • %ProgramFiles%\drweb386\<File name>.vbs
  • %ProgramFiles%\drwebscd\<File name>.vbs
  • %ProgramFiles%\drwebupw\<File name>.vbs
  • %ProgramFiles%\drwebwcl\<File name>.vbs
  • %ProgramFiles%\aswupdsv\<File name>.vbs
  • %ProgramFiles%\drwreg\<File name>.vbs
  • %ProgramFiles%\ecmd\<File name>.vbs
  • %ProgramFiles%\egni\<File name>.vbs
  • %ProgramFiles%\ehsniffer\<File name>.vbs
  • %ProgramFiles%\ekrn\<File name>.vbs
  • %ProgramFiles%\elementclient\<File name>.vbs
  • %ProgramFiles%\etherd\<File name>.vbs
  • %ProgramFiles%\eudora\<File name>.vbs
  • %ProgramFiles%\dpatrolq\<File name>.vbs
  • %ProgramFiles%\dnf\<File name>.vbs
  • %ProgramFiles%\dvd maker\<File name>.vbs
  • %ProgramFiles%\drvmap\<File name>.vbs
  • %ProgramFiles%\drvirus\<File name>.vbs
  • %ProgramFiles%\dislite\<File name>.vbs
  • %ProgramFiles%\directftp\<File name>.vbs
  • %ProgramFiles%\cmgrdian\<File name>.vbs
  • %CommonProgramFiles%\<File name>.vbs
  • %ProgramFiles%\copyx64\<File name>.vbs
  • %ProgramFiles%\courier\<File name>.vbs
  • %ProgramFiles%\cpd\<File name>.vbs
  • %ProgramFiles%\csendto\<File name>.vbs
  • %ProgramFiles%\bdagent\<File name>.vbs
  • %ProgramFiles%\cssexc\<File name>.vbs
  • %ProgramFiles%\custsetup\<File name>.vbs
  • %ProgramFiles%\bdnews\<File name>.vbs
  • %ProgramFiles%\cuteftp\<File name>.vbs
  • %ProgramFiles%\dbtool\<File name>.vbs
  • %ProgramFiles%\defensewall\<File name>.vbs
  • %ProgramFiles%\defwatch\<File name>.vbs
  • %ProgramFiles%\dekaron\<File name>.vbs
  • %ProgramFiles%\digsby\<File name>.vbs
  • %ProgramFiles%\digsby-app\<File name>.vbs
  • %ProgramFiles%\custinstall\<File name>.vbs
  • %ProgramFiles%\clrcche\<File name>.vbs
  • %ProgramFiles%\clisvc\<File name>.vbs
  • %ProgramFiles%\dbconvert\<File name>.vbs
  • %WINDIR%\web\<File name>.vbs
  • %ProgramFiles%\ewidoctrl\<File name>.vbs
  • %ProgramFiles%\avsynmgr\<File name>.vbs
  • %ProgramFiles%\aim6\<File name>.vbs
  • %ProgramFiles%\aimpro\<File name>.vbs
  • %ProgramFiles%\airdefense\<File name>.vbs
  • %ProgramFiles%\almon\<File name>.vbs
  • %ProgramFiles%\alsvc\<File name>.vbs
  • %ProgramFiles%\amon\<File name>.vbs
  • %ProgramFiles%\amsn\<File name>.vbs
  • %ProgramFiles%\anti-trojan\<File name>.vbs
  • %ProgramFiles%\antivirus\<File name>.vbs
  • %ProgramFiles%\aoltbserver\<File name>.vbs
  • %ProgramFiles%\armor2net\<File name>.vbs
  • %ProgramFiles%\armorsurf\<File name>.vbs
  • %ProgramFiles%\ash\<File name>.vbs
  • %ProgramFiles%\ashavast\<File name>.vbs
  • %ProgramFiles%\ashavsrv\<File name>.vbs
  • %ProgramFiles%\ashchest\<File name>.vbs
  • %ProgramFiles%\ashdisp\<File name>.vbs
  • %ProgramFiles%\ashdug\<File name>.vbs
  • %ProgramFiles%\ageofconan\<File name>.vbs
  • %ProgramFiles%\ashenhcd\<File name>.vbs
  • %ProgramFiles%\agb5\<File name>.vbs
  • %ProgramFiles%\ackwin32\<File name>.vbs
  • C:\far2\addons\<File name>.vbs
  • C:\far2\documentation\<File name>.vbs
  • C:\far2\encyclopedia\<File name>.vbs
  • C:\far2\fexcept\<File name>.vbs
  • C:\far2\plugins\<File name>.vbs
  • C:\far2\pluginsdk\<File name>.vbs
  • C:\msocache\all users\<File name>.vbs
  • C:\perflogs\admin\<File name>.vbs
  • %ProgramFiles%\360tray\<File name>.vbs
  • %ProgramFiles%\a2cmd\<File name>.vbs
  • %ProgramFiles%\a2guard\<File name>.vbs
  • %ProgramFiles%\a2hijackfree\<File name>.vbs
  • %ProgramFiles%\a2scan\<File name>.vbs
  • %ProgramFiles%\a2service\<File name>.vbs
  • %ProgramFiles%\a2start\<File name>.vbs
  • %ProgramFiles%\a2upd\<File name>.vbs
  • %ProgramFiles%\a2wizard\<File name>.vbs
  • %ProgramFiles%\aavshield\<File name>.vbs
  • %ProgramFiles%\about\<File name>.vbs
  • %ProgramFiles%\admunch\<File name>.vbs
  • %ProgramFiles%\ashlogv\<File name>.vbs
  • %ProgramFiles%\ahnsd\<File name>.vbs
  • %ProgramFiles%\ashmaisv\<File name>.vbs
  • %ProgramFiles%\avgfwsrv\<File name>.vbs
  • %ProgramFiles%\avgnpdln\<File name>.vbs
  • %ProgramFiles%\avgnpsvc\<File name>.vbs
  • %ProgramFiles%\avgrssvc\<File name>.vbs
  • %ProgramFiles%\avgscan\<File name>.vbs
  • %ProgramFiles%\avgupden\<File name>.vbs
  • %ProgramFiles%\avgupsvc\<File name>.vbs
  • %ProgramFiles%\avgvv\<File name>.vbs
  • %ProgramFiles%\avgw\<File name>.vbs
  • %ProgramFiles%\avgwizfw\<File name>.vbs
  • %ProgramFiles%\avinitnt\<File name>.vbs
  • %ProgramFiles%\avkserv\<File name>.vbs
  • %ProgramFiles%\avkservice\<File name>.vbs
  • %ProgramFiles%\avkwctl\<File name>.vbs
  • %ProgramFiles%\avnotify\<File name>.vbs
  • %ProgramFiles%\avpcc\<File name>.vbs
  • %ProgramFiles%\avpm\<File name>.vbs
  • %ProgramFiles%\avscan\<File name>.vbs
  • %ProgramFiles%\avgemc\<File name>.vbs
  • %ProgramFiles%\avgcc\<File name>.vbs
  • %ProgramFiles%\avginet\<File name>.vbs
  • %ProgramFiles%\avgdiag\<File name>.vbs
  • %ProgramFiles%\avgamsvr\<File name>.vbs
  • %ProgramFiles%\ashpopwz\<File name>.vbs
  • %ProgramFiles%\ashserv\<File name>.vbs
  • %ProgramFiles%\ashsimp2\<File name>.vbs
  • %ProgramFiles%\ashsimpl\<File name>.vbs
  • %ProgramFiles%\ashskpcc\<File name>.vbs
  • %ProgramFiles%\ashskpck\<File name>.vbs
  • %ProgramFiles%\ashupd\<File name>.vbs
  • %ProgramFiles%\ashwebsv\<File name>.vbs
  • %ProgramFiles%\ash_updatemediator\<File name>.vbs
  • %ProgramFiles%\b2\<File name>.vbs
  • %ProgramFiles%\backweb-4476822\<File name>.vbs
  • %ProgramFiles%\aswregsvr\<File name>.vbs
  • %ProgramFiles%\autostartexplorer\<File name>.vbs
  • %ProgramFiles%\autotrace\<File name>.vbs
  • %ProgramFiles%\avadmin\<File name>.vbs
  • %ProgramFiles%\avcenter\<File name>.vbs
  • %ProgramFiles%\avciman\<File name>.vbs
  • %ProgramFiles%\avcmd\<File name>.vbs
  • %ProgramFiles%\avconfig\<File name>.vbs
  • %ProgramFiles%\avconsol\<File name>.vbs
  • %ProgramFiles%\ashquick\<File name>.vbs
  • %ProgramFiles%\autodown\<File name>.vbs
  • %WINDIR%\system\<File name>.vbs
  • %ProgramFiles%\exit_av\<File name>.vbs
  • %ProgramFiles%\fameh32\<File name>.vbs
  • %ProgramFiles%\isuac\<File name>.vbs
  • %ProgramFiles%\itunes\<File name>.vbs
  • %ProgramFiles%\java\<File name>.vbs
  • %ProgramFiles%\k-meleon\<File name>.vbs
  • %ProgramFiles%\kav\<File name>.vbs
  • %ProgramFiles%\kavmm\<File name>.vbs
  • %ProgramFiles%\kavpf\<File name>.vbs
  • %ProgramFiles%\kavpfw\<File name>.vbs
  • %ProgramFiles%\kavstart\<File name>.vbs
  • %ProgramFiles%\kavsvc\<File name>.vbs
  • %ProgramFiles%\konnekt\<File name>.vbs
  • %ProgramFiles%\launcher\<File name>.vbs
  • %ProgramFiles%\licmgr\<File name>.vbs
  • %ProgramFiles%\livesrv\<File name>.vbs
  • %ProgramFiles%\liveupdate\<File name>.vbs
  • %ProgramFiles%\logwatnt\<File name>.vbs
  • %ProgramFiles%\lotroclient\<File name>.vbs
  • %ProgramFiles%\lpfw\<File name>.vbs
  • %ProgramFiles%\lucallbackproxy\<File name>.vbs
  • %ProgramFiles%\issvc\<File name>.vbs
  • %ProgramFiles%\lucheck\<File name>.vbs
  • %ProgramFiles%\ispwdsvc\<File name>.vbs
  • %ProgramFiles%\isafe\<File name>.vbs
  • %ProgramFiles%\ih8run\<File name>.vbs
  • %ProgramFiles%\ilaunchr\<File name>.vbs
  • %ProgramFiles%\imapp\<File name>.vbs
  • %ProgramFiles%\imnotfy\<File name>.vbs
  • %ProgramFiles%\impcnt\<File name>.vbs
  • %ProgramFiles%\incmail\<File name>.vbs
  • %ProgramFiles%\inocit\<File name>.vbs
  • %ProgramFiles%\inorpc\<File name>.vbs
  • %ProgramFiles%\inort\<File name>.vbs
  • %ProgramFiles%\inotask\<File name>.vbs
  • %ProgramFiles%\inouptng\<File name>.vbs
  • %ProgramFiles%\inphasenxd\<File name>.vbs
  • %ProgramFiles%\installcavs\<File name>.vbs
  • %ProgramFiles%\installlicense\<File name>.vbs
  • %ProgramFiles%\installlsp\<File name>.vbs
  • %ProgramFiles%\instlsp\<File name>.vbs
  • %ProgramFiles%\internet explorer\<File name>.vbs
  • %ProgramFiles%\iris\<File name>.vbs
  • %ProgramFiles%\iron\<File name>.vbs
  • %ProgramFiles%\ispnews\<File name>.vbs
  • %ProgramFiles%\luconfig\<File name>.vbs
  • %ProgramFiles%\luinit\<File name>.vbs
  • %ProgramFiles%\luupdate\<File name>.vbs
  • %ProgramFiles%\mp3tray\<File name>.vbs
  • %ProgramFiles%\mpeng\<File name>.vbs
  • %ProgramFiles%\mpftray\<File name>.vbs
  • %ProgramFiles%\mpssvc\<File name>.vbs
  • %ProgramFiles%\msbuild\<File name>.vbs
  • %ProgramFiles%\msimn\<File name>.vbs
  • %ProgramFiles%\msmpsvc\<File name>.vbs
  • %ProgramFiles%\ezantivirusregistrationcheck\<File name>.vbs
  • %ProgramFiles%\msn6\<File name>.vbs
  • %ProgramFiles%\mva\<File name>.vbs
  • %ProgramFiles%\mvc\<File name>.vbs
  • %ProgramFiles%\myagtsvc\<File name>.vbs
  • %ProgramFiles%\myagttry\<File name>.vbs
  • %ProgramFiles%\navapsvc\<File name>.vbs
  • %ProgramFiles%\navlu32\<File name>.vbs
  • %ProgramFiles%\navstub\<File name>.vbs
  • %ProgramFiles%\navw32\<File name>.vbs
  • %ProgramFiles%\mp3theater\<File name>.vbs
  • %ProgramFiles%\msnmsgr\<File name>.vbs
  • %ProgramFiles%\mp3toystray\<File name>.vbs
  • %ProgramFiles%\mp3toys\<File name>.vbs
  • %ProgramFiles%\monsysnt\<File name>.vbs
  • %ProgramFiles%\monlite\<File name>.vbs
  • %ProgramFiles%\magent\<File name>.vbs
  • %ProgramFiles%\malwareremoval\<File name>.vbs
  • %ProgramFiles%\maplestory\<File name>.vbs
  • %ProgramFiles%\maxthon\<File name>.vbs
  • %ProgramFiles%\mcmnhdlr\<File name>.vbs
  • %ProgramFiles%\mcregwiz\<File name>.vbs
  • %ProgramFiles%\mcshield\<File name>.vbs
  • %ProgramFiles%\iexplore\<File name>.vbs
  • %ProgramFiles%\mcupdmgr\<File name>.vbs
  • %ProgramFiles%\ih8\<File name>.vbs
  • %ProgramFiles%\memstring\<File name>.vbs
  • %ProgramFiles%\microsoft analysis services\<File name>.vbs
  • %ProgramFiles%\microsoft office\<File name>.vbs
  • %ProgramFiles%\microsoft sql server compact edition\<File name>.vbs
  • %ProgramFiles%\microsoft sync framework\<File name>.vbs
  • %ProgramFiles%\microsoft synchronization services\<File name>.vbs
  • %ProgramFiles%\mir3game\<File name>.vbs
  • %ProgramFiles%\miranda32\<File name>.vbs
  • %ProgramFiles%\luna\<File name>.vbs
  • %ProgramFiles%\miro\<File name>.vbs
  • %ProgramFiles%\mfpmp\<File name>.vbs
  • %ProgramFiles%\f-sched\<File name>.vbs
  • %ProgramFiles%\mcvsshld\<File name>.vbs
  • %ProgramFiles%\cavq\<File name>.vbs
  • %ProgramFiles%\fsav\<File name>.vbs
  • %ProgramFiles%\fsav32\<File name>.vbs
  • %ProgramFiles%\fsavaui\<File name>.vbs
  • %ProgramFiles%\fsavgui\<File name>.vbs
  • %ProgramFiles%\fsavstrt\<File name>.vbs
  • %ProgramFiles%\fsavwsch\<File name>.vbs
  • %ProgramFiles%\fsavwscr\<File name>.vbs
  • %ProgramFiles%\fsbwsys\<File name>.vbs
  • %ProgramFiles%\fsdbuh\<File name>.vbs
  • %ProgramFiles%\fsdc\<File name>.vbs
  • %ProgramFiles%\fsdfwd\<File name>.vbs
  • %ProgramFiles%\fsdiag\<File name>.vbs
  • %ProgramFiles%\fsdiagui\<File name>.vbs
  • %ProgramFiles%\fsfwwsch\<File name>.vbs
  • %ProgramFiles%\fsfwwscr\<File name>.vbs
  • %ProgramFiles%\fsgetwab\<File name>.vbs
  • %ProgramFiles%\fsgk32\<File name>.vbs
  • %ProgramFiles%\fsgk32st\<File name>.vbs
  • %ProgramFiles%\fsguidll\<File name>.vbs
  • %ProgramFiles%\fsauach\<File name>.vbs
  • %ProgramFiles%\fsguiexe\<File name>.vbs
  • %ProgramFiles%\fsaua\<File name>.vbs
  • %ProgramFiles%\freshclam\<File name>.vbs
  • %ProgramFiles%\far\<File name>.vbs
  • %ProgramFiles%\fch32\<File name>.vbs
  • %ProgramFiles%\fdm\<File name>.vbs
  • %ProgramFiles%\fdmwi\<File name>.vbs
  • %ProgramFiles%\filezilla\<File name>.vbs
  • %ProgramFiles%\firebird\<File name>.vbs
  • %ProgramFiles%\firefox\<File name>.vbs
  • %ProgramFiles%\firesvc\<File name>.vbs
  • %ProgramFiles%\firetray\<File name>.vbs
  • %ProgramFiles%\flashfxp\<File name>.vbs
  • %ProgramFiles%\flashgot\<File name>.vbs
  • %ProgramFiles%\flock\<File name>.vbs
  • %ProgramFiles%\foxit\<File name>.vbs
  • %ProgramFiles%\fpavserver\<File name>.vbs
  • %ProgramFiles%\fpavupdm\<File name>.vbs
  • %ProgramFiles%\fprottray\<File name>.vbs
  • %ProgramFiles%\fpscan\<File name>.vbs
  • %ProgramFiles%\fptrayproc\<File name>.vbs
  • %ProgramFiles%\fpwin\<File name>.vbs
  • %ProgramFiles%\fsample\<File name>.vbs
  • %ProgramFiles%\fshdll32\<File name>.vbs
  • %ProgramFiles%\fshelp\<File name>.vbs
  • %ProgramFiles%\fsihcomp\<File name>.vbs
  • %ProgramFiles%\gnotify\<File name>.vbs
  • %ProgramFiles%\googledesktop\<File name>.vbs
  • %ProgramFiles%\googletalk\<File name>.vbs
  • %ProgramFiles%\googleupdate\<File name>.vbs
  • %ProgramFiles%\guardgni\<File name>.vbs
  • %ProgramFiles%\guardnt\<File name>.vbs
  • %ProgramFiles%\gw\<File name>.vbs
  • %ProgramFiles%\icqlite\<File name>.vbs
  • %ProgramFiles%\helpctr\<File name>.vbs
  • %ProgramFiles%\hipsdiag\<File name>.vbs
  • %ProgramFiles%\hregmon\<File name>.vbs
  • %ProgramFiles%\hrres\<File name>.vbs
  • %ProgramFiles%\hsockpe\<File name>.vbs
  • %ProgramFiles%\httplook\<File name>.vbs
  • %ProgramFiles%\iamapp\<File name>.vbs
  • %ProgramFiles%\iamserv\<File name>.vbs
  • %ProgramFiles%\icq\<File name>.vbs
  • %ProgramFiles%\gg\<File name>.vbs
  • %ProgramFiles%\helper\<File name>.vbs
  • %ProgramFiles%\giantantispywareupdater\<File name>.vbs
  • %ProgramFiles%\giantantispywaremain\<File name>.vbs
  • %ProgramFiles%\ge\<File name>.vbs
  • %ProgramFiles%\gcasserv\<File name>.vbs
  • %ProgramFiles%\fsihs\<File name>.vbs
  • %ProgramFiles%\fslaunch\<File name>.vbs
  • %ProgramFiles%\fsm32\<File name>.vbs
  • %ProgramFiles%\fsma32\<File name>.vbs
  • %ProgramFiles%\fsmb32\<File name>.vbs
  • %ProgramFiles%\fspc\<File name>.vbs
  • %ProgramFiles%\fspex\<File name>.vbs
  • %ProgramFiles%\ieregfix\<File name>.vbs
  • %ProgramFiles%\fsqh\<File name>.vbs
  • %ProgramFiles%\ieuser\<File name>.vbs
  • %ProgramFiles%\fssg\<File name>.vbs
  • %ProgramFiles%\fsstm\<File name>.vbs
  • %ProgramFiles%\fssw\<File name>.vbs
  • %ProgramFiles%\fstlui\<File name>.vbs
  • %ProgramFiles%\fsuninst\<File name>.vbs
  • %ProgramFiles%\fsus\<File name>.vbs
  • %ProgramFiles%\ftpte\<File name>.vbs
  • %ProgramFiles%\gc\<File name>.vbs
  • %ProgramFiles%\fshotfix\<File name>.vbs
  • %ProgramFiles%\gcasdtserv\<File name>.vbs
  • %ProgramFiles%\fssm32\<File name>.vbs
  • D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs
Sets the 'hidden' attribute to the following files
  • <Drive name for removable media>:\<File name>.vbs
  • %ProgramFiles%\scanningprocess\<File name>.vbs
  • %ProgramFiles%\sched\<File name>.vbs
  • %ProgramFiles%\sdhelp\<File name>.vbs
  • %ProgramFiles%\sdinvoker\<File name>.vbs
  • %ProgramFiles%\sdloader\<File name>.vbs
  • %ProgramFiles%\sdraw\<File name>.vbs
  • %ProgramFiles%\sdtrayapp\<File name>.vbs
  • %ProgramFiles%\seamonkey\<File name>.vbs
  • %ProgramFiles%\seccenter\<File name>.vbs
  • %ProgramFiles%\sfagent\<File name>.vbs
  • %ProgramFiles%\sigtool\<File name>.vbs
  • %ProgramFiles%\simpress\<File name>.vbs
  • %ProgramFiles%\sitecli\<File name>.vbs
  • %ProgramFiles%\skype\<File name>.vbs
  • %ProgramFiles%\skypepm\<File name>.vbs
  • %ProgramFiles%\smartftp\<File name>.vbs
  • %ProgramFiles%\smath\<File name>.vbs
  • %ProgramFiles%\smc\<File name>.vbs
  • %ProgramFiles%\sndsrvc\<File name>.vbs
  • %ProgramFiles%\scanner\<File name>.vbs
  • %ProgramFiles%\sniffer\<File name>.vbs
  • %ProgramFiles%\scalc\<File name>.vbs
  • %ProgramFiles%\savscan\<File name>.vbs
  • %ProgramFiles%\ravtimer\<File name>.vbs
  • %ProgramFiles%\rcimlby\<File name>.vbs
  • %ProgramFiles%\realmon\<File name>.vbs
  • %ProgramFiles%\reference assemblies\<File name>.vbs
  • %ProgramFiles%\register\<File name>.vbs
  • %ProgramFiles%\removeit\<File name>.vbs
  • %ProgramFiles%\remover\<File name>.vbs
  • %ProgramFiles%\rescue\<File name>.vbs
  • %ProgramFiles%\rfwmain\<File name>.vbs
  • %ProgramFiles%\rq\<File name>.vbs
  • %ProgramFiles%\rtvscan\<File name>.vbs
  • %ProgramFiles%\rulaunch\<File name>.vbs
  • %ProgramFiles%\runsetup\<File name>.vbs
  • %ProgramFiles%\safari\<File name>.vbs
  • %ProgramFiles%\sarcli\<File name>.vbs
  • %ProgramFiles%\sargui\<File name>.vbs
  • %ProgramFiles%\savadminservice\<File name>.vbs
  • %ProgramFiles%\savmain\<File name>.vbs
  • %ProgramFiles%\savprogress\<File name>.vbs
  • %ProgramFiles%\sbase\<File name>.vbs
  • %ProgramFiles%\so3d\<File name>.vbs
  • %ProgramFiles%\soffice\<File name>.vbs
  • %ProgramFiles%\spamcfg\<File name>.vbs
  • %ProgramFiles%\tca\<File name>.vbs
  • %ProgramFiles%\teatimer\<File name>.vbs
  • %ProgramFiles%\tgsvcstp\<File name>.vbs
  • %ProgramFiles%\thebat\<File name>.vbs
  • %ProgramFiles%\thgnard\<File name>.vbs
  • %ProgramFiles%\thunderbird\<File name>.vbs
  • %ProgramFiles%\tmas\<File name>.vbs
  • %ProgramFiles%\tmlisten\<File name>.vbs
  • %ProgramFiles%\trtddptr\<File name>.vbs
  • %ProgramFiles%\tmntsrv\<File name>.vbs
  • %ProgramFiles%\tmproxy\<File name>.vbs
  • %ProgramFiles%\tnbutil\<File name>.vbs
  • %ProgramFiles%\totalcmd\<File name>.vbs
  • %ProgramFiles%\tracelog\<File name>.vbs
  • %ProgramFiles%\traymon\<File name>.vbs
  • %ProgramFiles%\trillian\<File name>.vbs
  • %ProgramFiles%\trojanguarder\<File name>.vbs
  • %ProgramFiles%\trojanhunter\<File name>.vbs
  • %ProgramFiles%\sysinfo\<File name>.vbs
  • %ProgramFiles%\tbmon\<File name>.vbs
  • %ProgramFiles%\symwsc\<File name>.vbs
  • %ProgramFiles%\symsport\<File name>.vbs
  • %ProgramFiles%\symproxysvc\<File name>.vbs
  • %ProgramFiles%\spider\<File name>.vbs
  • %ProgramFiles%\spiderml\<File name>.vbs
  • %ProgramFiles%\spidernt\<File name>.vbs
  • %ProgramFiles%\spiderui\<File name>.vbs
  • %ProgramFiles%\sporder\<File name>.vbs
  • %ProgramFiles%\spybotsd\<File name>.vbs
  • %ProgramFiles%\sro_client\<File name>.vbs
  • %ProgramFiles%\start_diag\<File name>.vbs
  • %ProgramFiles%\ravmon\<File name>.vbs
  • %ProgramFiles%\streetsolkshim\<File name>.vbs
  • %ProgramFiles%\stopsignav\<File name>.vbs
  • %ProgramFiles%\svcntaux\<File name>.vbs
  • %ProgramFiles%\swagent\<File name>.vbs
  • %ProgramFiles%\swdoctor\<File name>.vbs
  • %ProgramFiles%\swdsvc\<File name>.vbs
  • %ProgramFiles%\sweb\<File name>.vbs
  • %ProgramFiles%\swriter\<File name>.vbs
  • %ProgramFiles%\symantecrootinstaller\<File name>.vbs
  • %ProgramFiles%\symlcsvc\<File name>.vbs
  • %ProgramFiles%\spbbcsvc\<File name>.vbs
  • %ProgramFiles%\submitfiles\<File name>.vbs
  • %ProgramFiles%\tmpfw\<File name>.vbs
  • %ProgramFiles%\rat\<File name>.vbs
  • %ProgramFiles%\pxsupport\<File name>.vbs
  • %ProgramFiles%\oaui\<File name>.vbs
  • %ProgramFiles%\ofcpfwsvc\<File name>.vbs
  • %ProgramFiles%\oget\<File name>.vbs
  • %ProgramFiles%\oladdin\<File name>.vbs
  • %ProgramFiles%\onaccessinstaller\<File name>.vbs
  • %ProgramFiles%\opera\<File name>.vbs
  • %ProgramFiles%\oscheck\<File name>.vbs
  • %ProgramFiles%\outlook\<File name>.vbs
  • %ProgramFiles%\outpost\<File name>.vbs
  • %ProgramFiles%\partin\<File name>.vbs
  • %ProgramFiles%\partin9x\<File name>.vbs
  • %ProgramFiles%\partinfo\<File name>.vbs
  • %ProgramFiles%\partinnt\<File name>.vbs
  • %ProgramFiles%\pavfires\<File name>.vbs
  • %ProgramFiles%\pavfnsvr\<File name>.vbs
  • %ProgramFiles%\pavkre\<File name>.vbs
  • %ProgramFiles%\pavprot\<File name>.vbs
  • %ProgramFiles%\pavproxy\<File name>.vbs
  • %ProgramFiles%\pavprsrv\<File name>.vbs
  • %ProgramFiles%\oasrv\<File name>.vbs
  • %ProgramFiles%\pavsrv51\<File name>.vbs
  • %ProgramFiles%\nwservice\<File name>.vbs
  • %ProgramFiles%\nvcte\<File name>.vbs
  • %ProgramFiles%\netstatviewer\<File name>.vbs
  • %ProgramFiles%\netxray\<File name>.vbs
  • %ProgramFiles%\nisoptui\<File name>.vbs
  • %ProgramFiles%\nod\<File name>.vbs
  • %ProgramFiles%\nod32\<File name>.vbs
  • %ProgramFiles%\nod32krn\<File name>.vbs
  • %ProgramFiles%\nod32kui\<File name>.vbs
  • %ProgramFiles%\notifyha\<File name>.vbs
  • %ProgramFiles%\notstart\<File name>.vbs
  • %ProgramFiles%\npavtray\<File name>.vbs
  • %ProgramFiles%\npfmsg\<File name>.vbs
  • %ProgramFiles%\nsmdtr\<File name>.vbs
  • %ProgramFiles%\nssserv\<File name>.vbs
  • %ProgramFiles%\nsstray\<File name>.vbs
  • %ProgramFiles%\ntoskrnl\<File name>.vbs
  • %ProgramFiles%\ntrtscan\<File name>.vbs
  • %ProgramFiles%\ntxconfig\<File name>.vbs
  • %ProgramFiles%\nupgrade\<File name>.vbs
  • %ProgramFiles%\nvcod\<File name>.vbs
  • %ProgramFiles%\nvcut\<File name>.vbs
  • %ProgramFiles%\pccguide\<File name>.vbs
  • %ProgramFiles%\pccntmon\<File name>.vbs
  • %ProgramFiles%\pccpfw\<File name>.vbs
  • %ProgramFiles%\ps\<File name>.vbs
  • %ProgramFiles%\psctrls\<File name>.vbs
  • %ProgramFiles%\pshost\<File name>.vbs
  • %ProgramFiles%\psimsvc\<File name>.vbs
  • %ProgramFiles%\pxagent\<File name>.vbs
  • %ProgramFiles%\pxconsole\<File name>.vbs
  • %ProgramFiles%\pxl\<File name>.vbs
  • %ProgramFiles%\pxl1\<File name>.vbs
  • %ProgramFiles%\ragfree\<File name>.vbs
  • %ProgramFiles%\pxreset\<File name>.vbs
  • %ProgramFiles%\python\<File name>.vbs
  • %ProgramFiles%\qhwscsvc\<File name>.vbs
  • %ProgramFiles%\qip\<File name>.vbs
  • %ProgramFiles%\qklez\<File name>.vbs
  • %ProgramFiles%\qrtfix\<File name>.vbs
  • %ProgramFiles%\quaranti\<File name>.vbs
  • %ProgramFiles%\quickstart\<File name>.vbs
  • %ProgramFiles%\ragexe\<File name>.vbs
  • %ProgramFiles%\processviewer\<File name>.vbs
  • %ProgramFiles%\protect\<File name>.vbs
  • %ProgramFiles%\privatebrowser\<File name>.vbs
  • %ProgramFiles%\prevxsetup\<File name>.vbs
  • %ProgramFiles%\prevsrv\<File name>.vbs
  • %ProgramFiles%\pctav\<File name>.vbs
  • %ProgramFiles%\pertsk\<File name>.vbs
  • %ProgramFiles%\pidgin\<File name>.vbs
  • %ProgramFiles%\pm\<File name>.vbs
  • %ProgramFiles%\pm8flash\<File name>.vbs
  • %ProgramFiles%\pmagic\<File name>.vbs
  • %ProgramFiles%\pmagic9x\<File name>.vbs
  • %ProgramFiles%\pmagicbt\<File name>.vbs
  • %ProgramFiles%\rapget\<File name>.vbs
  • %ProgramFiles%\polutil\<File name>.vbs
  • %ProgramFiles%\pmagicnt\<File name>.vbs
  • %ProgramFiles%\ppfw\<File name>.vbs
  • %ProgramFiles%\pqboot32\<File name>.vbs
  • %ProgramFiles%\pqbw\<File name>.vbs
  • %ProgramFiles%\pqpe\<File name>.vbs
  • %ProgramFiles%\pqpe9x\<File name>.vbs
  • %ProgramFiles%\pqpent\<File name>.vbs
  • %ProgramFiles%\preconfig\<File name>.vbs
  • %ProgramFiles%\preupd\<File name>.vbs
  • %ProgramFiles%\pcctlcom\<File name>.vbs
  • %ProgramFiles%\postinstall\<File name>.vbs
  • %ProgramFiles%\twelvesky2\<File name>.vbs
  • %ProgramFiles%\uiscan\<File name>.vbs
  • %ProgramFiles%\una\<File name>.vbs
  • %PROGRAMDATA%\microsoft toolkit\<File name>.vbs
  • %PROGRAMDATA%\mozilla\<File name>.vbs
  • %PROGRAMDATA%\oracle\<File name>.vbs
  • %PROGRAMDATA%\package cache\<File name>.vbs
  • %PROGRAMDATA%\start menu\<File name>.vbs
  • %PROGRAMDATA%\sun\<File name>.vbs
  • %PROGRAMDATA%\templates\<File name>.vbs
  • C:\recovery\1195d5a8-f371-11e4-9c00-dd3082671db2\<File name>.vbs
  • %WINDIR%\cursors\<File name>.vbs
  • C:\totalcmd\language\<File name>.vbs
  • C:\users\public\<File name>.vbs
  • %HOMEPATH%\<File name>.vbs
  • %WINDIR%\addins\<File name>.vbs
  • %WINDIR%\appcompat\<File name>.vbs
  • %WINDIR%\apppatch\<File name>.vbs
  • %WINDIR%\assembly\<File name>.vbs
  • %WINDIR%\bitlockerdiscoveryvolumecontents\<File name>.vbs
  • %WINDIR%\branding\<File name>.vbs
  • %PROGRAMDATA%\microsoft\<File name>.vbs
  • %PROGRAMDATA%\microsoft help\<File name>.vbs
  • C:\users\default\<File name>.vbs
  • %WINDIR%\csc\<File name>.vbs
  • %PROGRAMDATA%\desktop\<File name>.vbs
  • %ProgramFiles(x86)%\msbuild\<File name>.vbs
  • %ProgramFiles(x86)%\opera\<File name>.vbs
  • %ProgramFiles(x86)%\pidgin\<File name>.vbs
  • %ProgramFiles(x86)%\qip 2012\<File name>.vbs
  • %ProgramFiles(x86)%\reference assemblies\<File name>.vbs
  • %ProgramFiles(x86)%\steam\<File name>.vbs
  • %ProgramFiles(x86)%\uninstall information\<File name>.vbs
  • %ProgramFiles(x86)%\winamp\<File name>.vbs
  • %ProgramFiles(x86)%\windows defender\<File name>.vbs
  • %ProgramFiles(x86)%\windows mail\<File name>.vbs
  • %ProgramFiles(x86)%\windows media player\<File name>.vbs
  • %ProgramFiles(x86)%\windows nt\<File name>.vbs
  • %ProgramFiles(x86)%\windows photo viewer\<File name>.vbs
  • %ProgramFiles(x86)%\windows portable devices\<File name>.vbs
  • %ProgramFiles(x86)%\windows sidebar\<File name>.vbs
  • %PROGRAMDATA%\adobe\<File name>.vbs
  • %PROGRAMDATA%\application data\<File name>.vbs
  • %PROGRAMDATA%\documents\<File name>.vbs
  • %ProgramFiles(x86)%\mozilla firefox\<File name>.vbs
  • %PROGRAMDATA%\favorites\<File name>.vbs
  • %WINDIR%\web\<File name>.vbs
  • %WINDIR%\debug\<File name>.vbs
  • %WINDIR%\remotepackages\<File name>.vbs
  • %WINDIR%\schcache\<File name>.vbs
  • %WINDIR%\schemas\<File name>.vbs
  • %WINDIR%\security\<File name>.vbs
  • %WINDIR%\serviceprofiles\<File name>.vbs
  • %WINDIR%\setup\<File name>.vbs
  • %WINDIR%\shellnew\<File name>.vbs
  • %WINDIR%\softwaredistribution\<File name>.vbs
  • %WINDIR%\speech\<File name>.vbs
  • %WINDIR%\digitallocker\<File name>.vbs
  • %WINDIR%\system\<File name>.vbs
  • %WINDIR%\syswow64\<File name>.vbs
  • %WINDIR%\tapi\<File name>.vbs
  • %WINDIR%\tasks\<File name>.vbs
  • %WINDIR%\temp\<File name>.vbs
  • %WINDIR%\tracing\<File name>.vbs
  • %WINDIR%\twain_32\<File name>.vbs
  • %WINDIR%\vss\<File name>.vbs
  • %WINDIR%\registration\<File name>.vbs
  • %WINDIR%\prefetch\<File name>.vbs
  • %WINDIR%\resources\<File name>.vbs
  • %WINDIR%\policydefinitions\<File name>.vbs
  • %WINDIR%\pla\<File name>.vbs
  • %WINDIR%\downloaded program files\<File name>.vbs
  • %WINDIR%\en-us\<File name>.vbs
  • %WINDIR%\fonts\<File name>.vbs
  • %WINDIR%\globalization\<File name>.vbs
  • %WINDIR%\help\<File name>.vbs
  • %WINDIR%\ime\<File name>.vbs
  • %WINDIR%\inf\<File name>.vbs
  • %WINDIR%\installer\<File name>.vbs
  • %ProgramFiles(x86)%\mirc\<File name>.vbs
  • %WINDIR%\l2schemas\<File name>.vbs
  • %ProgramFiles(x86)%\mozilla thunderbird\<File name>.vbs
  • %WINDIR%\logs\<File name>.vbs
  • %WINDIR%\microsoft.net\<File name>.vbs
  • %WINDIR%\migration\<File name>.vbs
  • %WINDIR%\modemlogs\<File name>.vbs
  • %WINDIR%\offline web pages\<File name>.vbs
  • %WINDIR%\panther\<File name>.vbs
  • %WINDIR%\pchealth\<File name>.vbs
  • %WINDIR%\performance\<File name>.vbs
  • %WINDIR%\livekernelreports\<File name>.vbs
  • %WINDIR%\ehome\<File name>.vbs
  • %WINDIR%\media\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft.net\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft visual studio 8\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft visual studio .net 2003\<File name>.vbs
  • %ProgramFiles%\virusnews\<File name>.vbs
  • %ProgramFiles%\vistaux\<File name>.vbs
  • %ProgramFiles%\visthlic\<File name>.vbs
  • %ProgramFiles%\visthupd\<File name>.vbs
  • %ProgramFiles%\vrfwsvc\<File name>.vbs
  • %ProgramFiles%\vrmonsvc\<File name>.vbs
  • %ProgramFiles%\vrrw32\<File name>.vbs
  • %ProgramFiles%\vshwin32\<File name>.vbs
  • %ProgramFiles%\vsmon\<File name>.vbs
  • %ProgramFiles%\vsserv\<File name>.vbs
  • %ProgramFiles%\vsstat\<File name>.vbs
  • %ProgramFiles%\wclose\<File name>.vbs
  • %ProgramFiles%\webfiltr\<File name>.vbs
  • %ProgramFiles%\webmoney\<File name>.vbs
  • %ProgramFiles%\webproxy\<File name>.vbs
  • %ProgramFiles%\webscanx\<File name>.vbs
  • %ProgramFiles%\wil\<File name>.vbs
  • %ProgramFiles%\viritexp\<File name>.vbs
  • %ProgramFiles%\vcrmon\<File name>.vbs
  • %ProgramFiles%\viruskeeper\<File name>.vbs
  • %ProgramFiles%\vettray\<File name>.vbs
  • %ProgramFiles%\vchk\<File name>.vbs
  • %ProgramFiles%\updclient\<File name>.vbs
  • %ProgramFiles%\uninstallcavs\<File name>.vbs
  • %ProgramFiles%\uninstaller\<File name>.vbs
  • %ProgramFiles%\uninstalllsp\<File name>.vbs
  • %ProgramFiles%\unoinfo\<File name>.vbs
  • %ProgramFiles%\unopkg\<File name>.vbs
  • %ProgramFiles%\unp_test\<File name>.vbs
  • %ProgramFiles%\up2date\<File name>.vbs
  • %ProgramFiles%\updater\<File name>.vbs
  • %ProgramFiles%\winaw32\<File name>.vbs
  • %ProgramFiles%\neowatchtray\<File name>.vbs
  • %ProgramFiles%\updaterui\<File name>.vbs
  • %ProgramFiles%\upsobmaker\<File name>.vbs
  • %ProgramFiles%\usdownloader\<File name>.vbs
  • %ProgramFiles%\uupd\<File name>.vbs
  • %ProgramFiles%\vba32ecm\<File name>.vbs
  • %ProgramFiles%\vba32ifs\<File name>.vbs
  • %ProgramFiles%\vba32ldr\<File name>.vbs
  • %ProgramFiles%\vba32pp3\<File name>.vbs
  • %ProgramFiles%\vbsntw\<File name>.vbs
  • %ProgramFiles%\uninstall information\<File name>.vbs
  • %ProgramFiles%\upgrepl\<File name>.vbs
  • %ProgramFiles%\winrar\<File name>.vbs
  • %ProgramFiles%\winbaram\<File name>.vbs
  • %ProgramFiles%\windows journal\<File name>.vbs
  • %ProgramFiles%\xcommsvr\<File name>.vbs
  • %ProgramFiles%\yahoomessenger\<File name>.vbs
  • %ProgramFiles%\yahoosync\<File name>.vbs
  • %ProgramFiles%\ybclient\<File name>.vbs
  • %ProgramFiles%\ymsgr_tray\<File name>.vbs
  • %ProgramFiles%\zapro\<File name>.vbs
  • %ProgramFiles%\zatutor\<File name>.vbs
  • %ProgramFiles%\viritsvc\<File name>.vbs
  • %ProgramFiles%\zauninst\<File name>.vbs
  • %ProgramFiles%\zonealarm\<File name>.vbs
  • %ProgramFiles(x86)%\adobe\<File name>.vbs
  • %CommonProgramFiles(x86)%\<File name>.vbs
  • %ProgramFiles(x86)%\google\<File name>.vbs
  • %ProgramFiles(x86)%\internet explorer\<File name>.vbs
  • %ProgramFiles(x86)%\k-lite codec pack\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft analysis services\<File name>.vbs
  • %ProgramFiles(x86)%\microsoft office\<File name>.vbs
  • %ProgramFiles%\wsctool\<File name>.vbs
  • %ProgramFiles%\zlclient\<File name>.vbs
  • %ProgramFiles%\wsm\<File name>.vbs
  • %ProgramFiles%\wsftpgui\<File name>.vbs
  • %ProgramFiles%\writespid\<File name>.vbs
  • %ProgramFiles%\wrctrl\<File name>.vbs
  • %ProgramFiles%\windows mail\<File name>.vbs
  • %ProgramFiles%\windows media player\<File name>.vbs
  • %ProgramFiles%\windows nt\<File name>.vbs
  • %ProgramFiles%\windows photo viewer\<File name>.vbs
  • %ProgramFiles%\windows portable devices\<File name>.vbs
  • %ProgramFiles%\windows sidebar\<File name>.vbs
  • %ProgramFiles%\windump\<File name>.vbs
  • %ProgramFiles%\wincmd32\<File name>.vbs
  • %ProgramFiles%\winmail\<File name>.vbs
  • %ProgramFiles%\windowlist\<File name>.vbs
  • %ProgramFiles%\winroute\<File name>.vbs
  • %ProgramFiles%\winssnotify\<File name>.vbs
  • %ProgramFiles%\wish\<File name>.vbs
  • %ProgramFiles%\wlloginproxy\<File name>.vbs
  • %ProgramFiles%\wlmail\<File name>.vbs
  • %ProgramFiles%\wltuser\<File name>.vbs
  • %ProgramFiles%\woool\<File name>.vbs
  • %ProgramFiles%\wow\<File name>.vbs
  • %ProgramFiles%\windows defender\<File name>.vbs
  • %ProgramFiles%\wradmin\<File name>.vbs
  • %ProgramFiles%\winss\<File name>.vbs
  • <SYSTEM32>\<File name>.vbs
  • %ProgramFiles%\neowatchlog\<File name>.vbs
  • %ProgramFiles%\msnmsgr\<File name>.vbs
  • %ProgramFiles%\cavmud\<File name>.vbs
  • %ProgramFiles%\cavoar\<File name>.vbs
  • %ProgramFiles%\cavq\<File name>.vbs
  • %ProgramFiles%\cavscons\<File name>.vbs
  • %ProgramFiles%\cavse\<File name>.vbs
  • %ProgramFiles%\cavsn\<File name>.vbs
  • %ProgramFiles%\cavsub\<File name>.vbs
  • %ProgramFiles%\cavsubmit\<File name>.vbs
  • %ProgramFiles%\cavumas\<File name>.vbs
  • %ProgramFiles%\cavuserupd\<File name>.vbs
  • %ProgramFiles%\cavvl\<File name>.vbs
  • %ProgramFiles%\ccapp\<File name>.vbs
  • %ProgramFiles%\ccevtmgr\<File name>.vbs
  • %ProgramFiles%\ccleaner\<File name>.vbs
  • %ProgramFiles%\ccproxy\<File name>.vbs
  • %ProgramFiles%\ccsetmgr\<File name>.vbs
  • %ProgramFiles%\cemrep\<File name>.vbs
  • %ProgramFiles%\chrome\<File name>.vbs
  • %ProgramFiles%\clamscan\<File name>.vbs
  • %ProgramFiles%\cavmr\<File name>.vbs
  • %ProgramFiles%\clamtray\<File name>.vbs
  • %ProgramFiles%\cavemsrv\<File name>.vbs
  • %ProgramFiles%\cavasm\<File name>.vbs
  • %ProgramFiles%\backweb-4476822\<File name>.vbs
  • %ProgramFiles%\bdagent\<File name>.vbs
  • %ProgramFiles%\bdmcon\<File name>.vbs
  • %ProgramFiles%\bdnews\<File name>.vbs
  • %ProgramFiles%\bdoesrv\<File name>.vbs
  • %ProgramFiles%\bdss\<File name>.vbs
  • %ProgramFiles%\bdsubmit\<File name>.vbs
  • %ProgramFiles%\bdsubmitwiz\<File name>.vbs
  • %ProgramFiles%\bdsurvey\<File name>.vbs
  • %ProgramFiles%\bdswitch\<File name>.vbs
  • %ProgramFiles%\bdwizreg\<File name>.vbs
  • %ProgramFiles%\blackd\<File name>.vbs
  • %ProgramFiles%\blackice\<File name>.vbs
  • %ProgramFiles%\blindman\<File name>.vbs
  • %ProgramFiles%\btini\<File name>.vbs
  • %ProgramFiles%\btinint\<File name>.vbs
  • %ProgramFiles%\cabalmain\<File name>.vbs
  • %ProgramFiles%\cafix\<File name>.vbs
  • %ProgramFiles%\cavapp\<File name>.vbs
  • %ProgramFiles%\cavaud\<File name>.vbs
  • %ProgramFiles%\clamwin\<File name>.vbs
  • %ProgramFiles%\claw95\<File name>.vbs
  • %ProgramFiles%\claw95cf\<File name>.vbs
  • %ProgramFiles%\dpatrolq\<File name>.vbs
  • %ProgramFiles%\drvctl\<File name>.vbs
  • %ProgramFiles%\drvirus\<File name>.vbs
  • %ProgramFiles%\drvmap\<File name>.vbs
  • %ProgramFiles%\drwadins\<File name>.vbs
  • %ProgramFiles%\drweb\<File name>.vbs
  • %ProgramFiles%\drweb32w\<File name>.vbs
  • %ProgramFiles%\drweb386\<File name>.vbs
  • %ProgramFiles%\etherd\<File name>.vbs
  • %ProgramFiles%\drwebscd\<File name>.vbs
  • %ProgramFiles%\drwebwcl\<File name>.vbs
  • %ProgramFiles%\drwreg\<File name>.vbs
  • %ProgramFiles%\dvd maker\<File name>.vbs
  • %ProgramFiles%\ecmd\<File name>.vbs
  • %ProgramFiles%\egni\<File name>.vbs
  • %ProgramFiles%\ehsniffer\<File name>.vbs
  • %ProgramFiles%\ekrn\<File name>.vbs
  • %ProgramFiles%\elementclient\<File name>.vbs
  • %ProgramFiles%\dislite\<File name>.vbs
  • %ProgramFiles%\dnf\<File name>.vbs
  • %ProgramFiles%\directftp\<File name>.vbs
  • %ProgramFiles%\digsby-app\<File name>.vbs
  • %ProgramFiles%\digsby\<File name>.vbs
  • %ProgramFiles%\cleaner3\<File name>.vbs
  • %ProgramFiles%\clisvc\<File name>.vbs
  • %ProgramFiles%\clrcche\<File name>.vbs
  • %ProgramFiles%\cmain\<File name>.vbs
  • %ProgramFiles%\cmgrdian\<File name>.vbs
  • %CommonProgramFiles%\<File name>.vbs
  • %ProgramFiles%\copyx64\<File name>.vbs
  • %ProgramFiles%\courier\<File name>.vbs
  • %ProgramFiles%\b2\<File name>.vbs
  • %ProgramFiles%\csendto\<File name>.vbs
  • %ProgramFiles%\cpd\<File name>.vbs
  • %ProgramFiles%\custinstall\<File name>.vbs
  • %ProgramFiles%\custsetup\<File name>.vbs
  • %ProgramFiles%\cuteftp\<File name>.vbs
  • %ProgramFiles%\dbconvert\<File name>.vbs
  • %ProgramFiles%\dbtool\<File name>.vbs
  • %ProgramFiles%\defensewall\<File name>.vbs
  • %ProgramFiles%\defwatch\<File name>.vbs
  • %ProgramFiles%\dekaron\<File name>.vbs
  • %ProgramFiles%\cleaner\<File name>.vbs
  • %ProgramFiles%\cssexc\<File name>.vbs
  • %ProgramFiles%\drwebupw\<File name>.vbs
  • %ProgramFiles%\avsynmgr\<File name>.vbs
  • %ProgramFiles%\avgvv\<File name>.vbs
  • %ProgramFiles%\agb5\<File name>.vbs
  • %ProgramFiles%\ageofconan\<File name>.vbs
  • %ProgramFiles%\ahnsd\<File name>.vbs
  • %ProgramFiles%\aim6\<File name>.vbs
  • %ProgramFiles%\aimpro\<File name>.vbs
  • %ProgramFiles%\airdefense\<File name>.vbs
  • %ProgramFiles%\almon\<File name>.vbs
  • %ProgramFiles%\alsvc\<File name>.vbs
  • %ProgramFiles%\amon\<File name>.vbs
  • %ProgramFiles%\amsn\<File name>.vbs
  • %ProgramFiles%\anti-trojan\<File name>.vbs
  • %ProgramFiles%\antivirus\<File name>.vbs
  • %ProgramFiles%\aoltbserver\<File name>.vbs
  • %ProgramFiles%\armor2net\<File name>.vbs
  • %ProgramFiles%\armorsurf\<File name>.vbs
  • %ProgramFiles%\ash\<File name>.vbs
  • %ProgramFiles%\ashavast\<File name>.vbs
  • %ProgramFiles%\ashavsrv\<File name>.vbs
  • %ProgramFiles%\ashchest\<File name>.vbs
  • %ProgramFiles%\admunch\<File name>.vbs
  • %ProgramFiles%\ashdisp\<File name>.vbs
  • %ProgramFiles%\ackwin32\<File name>.vbs
  • %ProgramFiles%\aavshield\<File name>.vbs
  • <Drive name for removable media>:\autorun.inf
  • C:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs
  • C:\far2\addons\<File name>.vbs
  • C:\far2\documentation\<File name>.vbs
  • C:\far2\encyclopedia\<File name>.vbs
  • C:\far2\fexcept\<File name>.vbs
  • C:\far2\plugins\<File name>.vbs
  • C:\far2\pluginsdk\<File name>.vbs
  • C:\msocache\all users\<File name>.vbs
  • C:\perflogs\admin\<File name>.vbs
  • %ProgramFiles%\360tray\<File name>.vbs
  • %ProgramFiles%\a2cmd\<File name>.vbs
  • %ProgramFiles%\a2guard\<File name>.vbs
  • %ProgramFiles%\a2hijackfree\<File name>.vbs
  • %ProgramFiles%\a2scan\<File name>.vbs
  • %ProgramFiles%\a2service\<File name>.vbs
  • %ProgramFiles%\a2start\<File name>.vbs
  • %ProgramFiles%\a2upd\<File name>.vbs
  • %ProgramFiles%\a2wizard\<File name>.vbs
  • %ProgramFiles%\about\<File name>.vbs
  • %ProgramFiles%\ashdug\<File name>.vbs
  • %ProgramFiles%\ashenhcd\<File name>.vbs
  • %ProgramFiles%\ashlogv\<File name>.vbs
  • %ProgramFiles%\avgemc\<File name>.vbs
  • %ProgramFiles%\avgfwsrv\<File name>.vbs
  • %ProgramFiles%\avginet\<File name>.vbs
  • %ProgramFiles%\avgnpdln\<File name>.vbs
  • %ProgramFiles%\avgnpsvc\<File name>.vbs
  • %ProgramFiles%\avgrssvc\<File name>.vbs
  • %ProgramFiles%\avgscan\<File name>.vbs
  • %ProgramFiles%\avgupden\<File name>.vbs
  • %ProgramFiles%\avpm\<File name>.vbs
  • %ProgramFiles%\avgupsvc\<File name>.vbs
  • %ProgramFiles%\avgw\<File name>.vbs
  • %ProgramFiles%\avgwizfw\<File name>.vbs
  • %ProgramFiles%\avinitnt\<File name>.vbs
  • %ProgramFiles%\avkserv\<File name>.vbs
  • %ProgramFiles%\avkservice\<File name>.vbs
  • %ProgramFiles%\avkwctl\<File name>.vbs
  • %ProgramFiles%\avnotify\<File name>.vbs
  • %ProgramFiles%\avpcc\<File name>.vbs
  • %ProgramFiles%\avgcc\<File name>.vbs
  • %ProgramFiles%\avgdiag\<File name>.vbs
  • %ProgramFiles%\avgamsvr\<File name>.vbs
  • %ProgramFiles%\avconsol\<File name>.vbs
  • %ProgramFiles%\avconfig\<File name>.vbs
  • %ProgramFiles%\ashpopwz\<File name>.vbs
  • %ProgramFiles%\ashquick\<File name>.vbs
  • %ProgramFiles%\ashserv\<File name>.vbs
  • %ProgramFiles%\ashsimp2\<File name>.vbs
  • %ProgramFiles%\ashsimpl\<File name>.vbs
  • %ProgramFiles%\ashskpcc\<File name>.vbs
  • %ProgramFiles%\ashskpck\<File name>.vbs
  • %ProgramFiles%\ashupd\<File name>.vbs
  • %ProgramFiles%\avscan\<File name>.vbs
  • %ProgramFiles%\ash_updatemediator\<File name>.vbs
  • %ProgramFiles%\ashwebsv\<File name>.vbs
  • %ProgramFiles%\aswupdsv\<File name>.vbs
  • %ProgramFiles%\autodown\<File name>.vbs
  • %ProgramFiles%\autostartexplorer\<File name>.vbs
  • %ProgramFiles%\autotrace\<File name>.vbs
  • %ProgramFiles%\avadmin\<File name>.vbs
  • %ProgramFiles%\avcenter\<File name>.vbs
  • %ProgramFiles%\avciman\<File name>.vbs
  • %ProgramFiles%\avcmd\<File name>.vbs
  • %ProgramFiles%\ashmaisv\<File name>.vbs
  • %ProgramFiles%\aswregsvr\<File name>.vbs
  • %ProgramFiles%\eudora\<File name>.vbs
  • %ProgramFiles%\ewidoctrl\<File name>.vbs
  • %ProgramFiles%\exit_av\<File name>.vbs
  • %ProgramFiles%\issvc\<File name>.vbs
  • %ProgramFiles%\isuac\<File name>.vbs
  • %ProgramFiles%\itunes\<File name>.vbs
  • %ProgramFiles%\java\<File name>.vbs
  • %ProgramFiles%\k-meleon\<File name>.vbs
  • %ProgramFiles%\kav\<File name>.vbs
  • %ProgramFiles%\kavmm\<File name>.vbs
  • %ProgramFiles%\kavpf\<File name>.vbs
  • %ProgramFiles%\lucallbackproxy\<File name>.vbs
  • %ProgramFiles%\kavpfw\<File name>.vbs
  • %ProgramFiles%\kavsvc\<File name>.vbs
  • %ProgramFiles%\konnekt\<File name>.vbs
  • %ProgramFiles%\launcher\<File name>.vbs
  • %ProgramFiles%\licmgr\<File name>.vbs
  • %ProgramFiles%\livesrv\<File name>.vbs
  • %ProgramFiles%\liveupdate\<File name>.vbs
  • %ProgramFiles%\logwatnt\<File name>.vbs
  • %ProgramFiles%\lotroclient\<File name>.vbs
  • %ProgramFiles%\ispnews\<File name>.vbs
  • %ProgramFiles%\ispwdsvc\<File name>.vbs
  • %ProgramFiles%\kavstart\<File name>.vbs
  • %ProgramFiles%\lpfw\<File name>.vbs
  • %ProgramFiles%\iris\<File name>.vbs
  • %ProgramFiles%\ih8run\<File name>.vbs
  • %ProgramFiles%\ilaunchr\<File name>.vbs
  • %ProgramFiles%\imapp\<File name>.vbs
  • %ProgramFiles%\imnotfy\<File name>.vbs
  • %ProgramFiles%\impcnt\<File name>.vbs
  • %ProgramFiles%\incmail\<File name>.vbs
  • %ProgramFiles%\inocit\<File name>.vbs
  • %ProgramFiles%\inorpc\<File name>.vbs
  • %ProgramFiles%\inort\<File name>.vbs
  • %ProgramFiles%\inotask\<File name>.vbs
  • %ProgramFiles%\inouptng\<File name>.vbs
  • %ProgramFiles%\inphasenxd\<File name>.vbs
  • %ProgramFiles%\installcavs\<File name>.vbs
  • %ProgramFiles%\installlicense\<File name>.vbs
  • %ProgramFiles%\installlsp\<File name>.vbs
  • %ProgramFiles%\instlsp\<File name>.vbs
  • %ProgramFiles%\internet explorer\<File name>.vbs
  • %ProgramFiles%\iron\<File name>.vbs
  • %ProgramFiles%\iexplore\<File name>.vbs
  • %ProgramFiles%\isafe\<File name>.vbs
  • %ProgramFiles%\navw32\<File name>.vbs
  • %ProgramFiles%\lucheck\<File name>.vbs
  • %ProgramFiles%\mp3theater\<File name>.vbs
  • %ProgramFiles%\mp3toystray\<File name>.vbs
  • %ProgramFiles%\mp3tray\<File name>.vbs
  • %ProgramFiles%\mpeng\<File name>.vbs
  • %ProgramFiles%\mpftray\<File name>.vbs
  • %ProgramFiles%\mpssvc\<File name>.vbs
  • %ProgramFiles%\msbuild\<File name>.vbs
  • %ProgramFiles%\msimn\<File name>.vbs
  • %ProgramFiles%\msmpsvc\<File name>.vbs
  • %ProgramFiles%\luconfig\<File name>.vbs
  • %ProgramFiles%\msn6\<File name>.vbs
  • %ProgramFiles%\mva\<File name>.vbs
  • %ProgramFiles%\mvc\<File name>.vbs
  • %ProgramFiles%\myagtsvc\<File name>.vbs
  • %ProgramFiles%\myagttry\<File name>.vbs
  • %ProgramFiles%\navapsvc\<File name>.vbs
  • %ProgramFiles%\navlu32\<File name>.vbs
  • %ProgramFiles%\navstub\<File name>.vbs
  • %ProgramFiles%\monsysnt\<File name>.vbs
  • %ProgramFiles%\monlite\<File name>.vbs
  • %ProgramFiles%\mp3toys\<File name>.vbs
  • %ProgramFiles%\miro\<File name>.vbs
  • %ProgramFiles%\miranda32\<File name>.vbs
  • %ProgramFiles%\luinit\<File name>.vbs
  • %ProgramFiles%\luupdate\<File name>.vbs
  • %ProgramFiles%\magent\<File name>.vbs
  • %ProgramFiles%\malwareremoval\<File name>.vbs
  • %ProgramFiles%\maplestory\<File name>.vbs
  • %ProgramFiles%\maxthon\<File name>.vbs
  • %ProgramFiles%\mcmnhdlr\<File name>.vbs
  • %ProgramFiles%\mcregwiz\<File name>.vbs
  • %ProgramFiles%\ieuser\<File name>.vbs
  • %ProgramFiles%\mcshield\<File name>.vbs
  • %ProgramFiles%\ih8\<File name>.vbs
  • %ProgramFiles%\mcvsshld\<File name>.vbs
  • %ProgramFiles%\mfpmp\<File name>.vbs
  • %ProgramFiles%\microsoft analysis services\<File name>.vbs
  • %ProgramFiles%\microsoft office\<File name>.vbs
  • %ProgramFiles%\microsoft sql server compact edition\<File name>.vbs
  • %ProgramFiles%\microsoft sync framework\<File name>.vbs
  • %ProgramFiles%\microsoft synchronization services\<File name>.vbs
  • %ProgramFiles%\mir3game\<File name>.vbs
  • %ProgramFiles%\mcupdmgr\<File name>.vbs
  • %ProgramFiles%\luna\<File name>.vbs
  • %ProgramFiles%\memstring\<File name>.vbs
  • %ProgramFiles%\ieregfix\<File name>.vbs
  • %ProgramFiles%\icqlite\<File name>.vbs
  • %ProgramFiles%\icq\<File name>.vbs
  • %ProgramFiles%\fsav\<File name>.vbs
  • %ProgramFiles%\fsav32\<File name>.vbs
  • %ProgramFiles%\fsavaui\<File name>.vbs
  • %ProgramFiles%\fsavgui\<File name>.vbs
  • %ProgramFiles%\fsavstrt\<File name>.vbs
  • %ProgramFiles%\fsavwsch\<File name>.vbs
  • %ProgramFiles%\fsavwscr\<File name>.vbs
  • %ProgramFiles%\fsbwsys\<File name>.vbs
  • %ProgramFiles%\fsdbuh\<File name>.vbs
  • %ProgramFiles%\fsdc\<File name>.vbs
  • %ProgramFiles%\fsdfwd\<File name>.vbs
  • %ProgramFiles%\fsdiag\<File name>.vbs
  • %ProgramFiles%\fsdiagui\<File name>.vbs
  • %ProgramFiles%\fsfwwsch\<File name>.vbs
  • %ProgramFiles%\fsfwwscr\<File name>.vbs
  • %ProgramFiles%\fsgetwab\<File name>.vbs
  • %ProgramFiles%\fsgk32\<File name>.vbs
  • %ProgramFiles%\fsample\<File name>.vbs
  • %ProgramFiles%\fpwin\<File name>.vbs
  • %ProgramFiles%\fsauach\<File name>.vbs
  • %ProgramFiles%\freshclam\<File name>.vbs
  • %ProgramFiles%\fptrayproc\<File name>.vbs
  • %ProgramFiles%\firesvc\<File name>.vbs
  • %ProgramFiles%\f-sched\<File name>.vbs
  • %ProgramFiles%\fameh32\<File name>.vbs
  • %ProgramFiles%\far\<File name>.vbs
  • %ProgramFiles%\fch32\<File name>.vbs
  • %ProgramFiles%\fdm\<File name>.vbs
  • %ProgramFiles%\fdmwi\<File name>.vbs
  • %ProgramFiles%\filezilla\<File name>.vbs
  • %ProgramFiles%\firebird\<File name>.vbs
  • %ProgramFiles%\fsgk32st\<File name>.vbs
  • %ProgramFiles%\navwnt\<File name>.vbs
  • %ProgramFiles%\firefox\<File name>.vbs
  • %ProgramFiles%\flashfxp\<File name>.vbs
  • %ProgramFiles%\flashgot\<File name>.vbs
  • %ProgramFiles%\flock\<File name>.vbs
  • %ProgramFiles%\foxit\<File name>.vbs
  • %ProgramFiles%\fpavserver\<File name>.vbs
  • %ProgramFiles%\fpavupdm\<File name>.vbs
  • %ProgramFiles%\fprottray\<File name>.vbs
  • %ProgramFiles%\fpscan\<File name>.vbs
  • %ProgramFiles%\ezantivirusregistrationcheck\<File name>.vbs
  • %ProgramFiles%\firetray\<File name>.vbs
  • %ProgramFiles%\fsqh\<File name>.vbs
  • %ProgramFiles%\fsguidll\<File name>.vbs
  • %ProgramFiles%\fshotfix\<File name>.vbs
  • %ProgramFiles%\giantantispywareupdater\<File name>.vbs
  • %ProgramFiles%\gnotify\<File name>.vbs
  • %ProgramFiles%\googledesktop\<File name>.vbs
  • %ProgramFiles%\googletalk\<File name>.vbs
  • %ProgramFiles%\googleupdate\<File name>.vbs
  • %ProgramFiles%\guardgni\<File name>.vbs
  • %ProgramFiles%\guardnt\<File name>.vbs
  • %ProgramFiles%\fsaua\<File name>.vbs
  • %ProgramFiles%\gw\<File name>.vbs
  • %ProgramFiles%\helper\<File name>.vbs
  • %ProgramFiles%\hipsdiag\<File name>.vbs
  • %ProgramFiles%\hregmon\<File name>.vbs
  • %ProgramFiles%\hrres\<File name>.vbs
  • %ProgramFiles%\hsockpe\<File name>.vbs
  • %ProgramFiles%\httplook\<File name>.vbs
  • %ProgramFiles%\iamapp\<File name>.vbs
  • %ProgramFiles%\iamserv\<File name>.vbs
  • %ProgramFiles%\ge\<File name>.vbs
  • %ProgramFiles%\helpctr\<File name>.vbs
  • %ProgramFiles%\giantantispywaremain\<File name>.vbs
  • %ProgramFiles%\gg\<File name>.vbs
  • %ProgramFiles%\gcasserv\<File name>.vbs
  • %ProgramFiles%\gcasdtserv\<File name>.vbs
  • %ProgramFiles%\fsihcomp\<File name>.vbs
  • %ProgramFiles%\fsihs\<File name>.vbs
  • %ProgramFiles%\fslaunch\<File name>.vbs
  • %ProgramFiles%\fsm32\<File name>.vbs
  • %ProgramFiles%\fsma32\<File name>.vbs
  • %ProgramFiles%\fsmb32\<File name>.vbs
  • %ProgramFiles%\fspc\<File name>.vbs
  • %ProgramFiles%\fsguiexe\<File name>.vbs
  • %ProgramFiles%\fspex\<File name>.vbs
  • %ProgramFiles%\fshdll32\<File name>.vbs
  • %ProgramFiles%\fssf\<File name>.vbs
  • %ProgramFiles%\fssm32\<File name>.vbs
  • %ProgramFiles%\fsstm\<File name>.vbs
  • %ProgramFiles%\fssw\<File name>.vbs
  • %ProgramFiles%\fstlui\<File name>.vbs
  • %ProgramFiles%\fsuninst\<File name>.vbs
  • %ProgramFiles%\fsus\<File name>.vbs
  • %ProgramFiles%\ftpte\<File name>.vbs
  • %ProgramFiles%\fshelp\<File name>.vbs
  • %ProgramFiles%\gc\<File name>.vbs
  • %ProgramFiles%\fssg\<File name>.vbs
  • D:\$recycle.bin\s-1-5-21-1960123792-2022915161-3775307078-1001\<File name>.vbs

Рекомендации по лечению

  1. В случае если операционная система способна загрузиться (в штатном режиме или режиме защиты от сбоев), скачайте лечащую утилиту Dr.Web CureIt! и выполните с ее помощью полную проверку вашего компьютера, а также используемых вами переносных носителей информации.
  2. Если загрузка операционной системы невозможна, измените настройки BIOS вашего компьютера, чтобы обеспечить возможность загрузки ПК с компакт-диска или USB-накопителя. Скачайте образ аварийного диска восстановления системы Dr.Web® LiveDisk или утилиту записи Dr.Web® LiveDisk на USB-накопитель, подготовьте соответствующий носитель. Загрузив компьютер с использованием данного носителя, выполните его полную проверку и лечение обнаруженных угроз.
Скачать Dr.Web

По серийному номеру

Выполните полную проверку системы с использованием Антивируса Dr.Web Light для macOS. Данный продукт можно загрузить с официального сайта Apple App Store.

На загруженной ОС выполните полную проверку всех дисковых разделов с использованием продукта Антивирус Dr.Web для Linux.

Скачать Dr.Web

По серийному номеру

  1. Если мобильное устройство функционирует в штатном режиме, загрузите и установите на него бесплатный антивирусный продукт Dr.Web для Android Light. Выполните полную проверку системы и используйте рекомендации по нейтрализации обнаруженных угроз.
  2. Если мобильное устройство заблокировано троянцем-вымогателем семейства Android.Locker (на экране отображается обвинение в нарушении закона, требование выплаты определенной денежной суммы или иное сообщение, мешающее нормальной работе с устройством), выполните следующие действия:
    • загрузите свой смартфон или планшет в безопасном режиме (в зависимости от версии операционной системы и особенностей конкретного мобильного устройства эта процедура может быть выполнена различными способами; обратитесь за уточнением к инструкции, поставляемой вместе с приобретенным аппаратом, или напрямую к его производителю);
    • после активации безопасного режима установите на зараженное устройство бесплатный антивирусный продукт Dr.Web для Android Light и произведите полную проверку системы, выполнив рекомендации по нейтрализации обнаруженных угроз;
    • выключите устройство и включите его в обычном режиме.

Подробнее о Dr.Web для Android

Демо бесплатно на 14 дней

Выдаётся при установке